PT-2015-6750 · Ibm+2 · Ibm Sdk+3
Publicado
2015-11-23
·
Atualizado
2019-06-19
·
CVE-2015-5006
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Java Security Components in IBM SDK, Java Technology Edition versions 8 before SR2
IBM Java Security Components in IBM SDK, Java Technology Edition versions 7 R1 before SR3 FP20
IBM Java Security Components in IBM SDK, Java Technology Edition versions 7 before SR9 FP20
IBM Java Security Components in IBM SDK, Java Technology Edition versions 6 R1 before SR8 FP15
IBM Java Security Components in IBM SDK, Java Technology Edition versions 6 before SR16 FP15
Description
The issue allows physically proximate attackers to obtain sensitive information by reading the Kerberos Credential Cache. An attacker with physical access to the system could exploit this to gain access to sensitive information.
Recommendations
For IBM Java Security Components in IBM SDK, Java Technology Edition version 8 before SR2, update to SR2 or later.
For IBM Java Security Components in IBM SDK, Java Technology Edition version 7 R1 before SR3 FP20, update to SR3 FP20 or later.
For IBM Java Security Components in IBM SDK, Java Technology Edition version 7 before SR9 FP20, update to SR9 FP20 or later.
For IBM Java Security Components in IBM SDK, Java Technology Edition version 6 R1 before SR8 FP15, update to SR8 FP15 or later.
For IBM Java Security Components in IBM SDK, Java Technology Edition version 6 before SR16 FP15, update to SR16 FP15 or later.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Aix
Ibm Sdk
Red Hat
Suse