CVE-2015-4843 is an unspecified vulnerability in Oracle Java SE 6u101, 7u85, 8u60, and Java SE Embedded 8u51, affecting the Libraries component. The vulnerability allows remote attackers to compromise confidentiality, integrity, and availability via unknown vectors. The specific details of the vulnerable function or code path have not been disclosed by Oracle.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (POC) exploit for CVE-2015-4843, a type confusion and heap overflow vulnerability in the Java Virtual Machine (JVM). The codebase is structured into two main demonstration modules: OverflowDemo and TypeConfusionDemo, both implemented in Java under the src/main/java directory. The OverflowDemo demonstrates how a heap overflow can occur between adjacent arrays, while the TypeConfusionDemo shows how type confusion can be exploited to execute methods of a fake class (FakeClass) in place of a real class (RealClass). The DisableSecurityManager module leverages these primitives to disable the Java SecurityManager by crafting a FakeClassLoader and using it to define and instantiate a class with elevated privileges. The exploit is designed to run on aarch64 architectures and is not effective on Morello due to architectural differences. The repository includes a Python script (idx_calculator.py) to assist in calculating memory offsets for the exploit. The exploit requires the ability to run arbitrary Java code with access to sun.misc.Unsafe and large heap allocations. Notable fingerprintable endpoints include a reference to a local certificate file (/home/centos/PL-chain.pem) and the use of the file:/// URL scheme for class loading. The repository is a research-oriented POC and does not include weaponized or automated exploitation features.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.