PT-2015-5503 · Ibm+2 · Ibm Java+3
Publicado
2015-05-13
·
Atualizado
2019-06-13
·
CVE-2015-1914
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Java versions prior to 7 R1 SR3
IBM Java versions prior to 7 SR9
IBM Java 6 R1 versions prior to SR8 FP4
IBM Java 6 versions prior to SR16 FP4
IBM Java 5.0 versions prior to SR16 FP10
Description
The issue allows remote attackers to bypass permission checks and obtain sensitive information via vectors related to the Java Virtual Machine. Additionally, a vulnerability in IBM SSL/TLS implementations could allow a remote attacker to downgrade the security of certain SSL/TLS connections, facilitating brute-force decryption of TLS/SSL traffic between vulnerable clients and servers using man-in-the-middle techniques.
Recommendations
For IBM Java 7 R1, update to SR3 or later.
For IBM Java 7, update to SR9 or later.
For IBM Java 6 R1, update to SR8 FP4 or later.
For IBM Java 6, update to SR16 FP4 or later.
For IBM Java 5.0, update to SR16 FP10 or later.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Aix
Ibm Java
Red Hat
Suse