PT-2015-5503 · Ibm+2 · Ibm Java+3

Publicado

2015-05-13

·

Atualizado

2019-06-13

·

CVE-2015-1914

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Java versions prior to 7 R1 SR3 IBM Java versions prior to 7 SR9 IBM Java 6 R1 versions prior to SR8 FP4 IBM Java 6 versions prior to SR16 FP4 IBM Java 5.0 versions prior to SR16 FP10
Description The issue allows remote attackers to bypass permission checks and obtain sensitive information via vectors related to the Java Virtual Machine. Additionally, a vulnerability in IBM SSL/TLS implementations could allow a remote attacker to downgrade the security of certain SSL/TLS connections, facilitating brute-force decryption of TLS/SSL traffic between vulnerable clients and servers using man-in-the-middle techniques.
Recommendations For IBM Java 7 R1, update to SR3 or later. For IBM Java 7, update to SR9 or later. For IBM Java 6 R1, update to SR8 FP4 or later. For IBM Java 6, update to SR16 FP4 or later. For IBM Java 5.0, update to SR16 FP10 or later.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-1914
RHSA-2015:1006
RHSA-2015:1007
RHSA-2015:1020
RHSA-2015:1021
RHSA-2015:1091
RHSA-2015_1006
RHSA-2015_1020
RHSA-2015_1021
SUSE-SU-2015:1073-1
SUSE-SU-2015:1161-1

Produtos afetados

Ibm Aix
Ibm Java
Red Hat
Suse