PT-2015-4110 · Ibm+2 · Ibm Sdk+3

Tomas Hoger

·

Published

2015-02-05

·

Updated

2019-07-16

·

CVE-2014-8891

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM SDK, Java Technology Edition versions 5.0 before SR16-FP9 IBM SDK, Java Technology Edition versions 6 before SR16-FP3 IBM SDK, Java Technology Edition versions 6R1 before SR8-FP3 IBM SDK, Java Technology Edition versions 7 before SR8-FP10 IBM SDK, Java Technology Edition versions 7R1 before SR2-FP10
Description The issue allows remote attackers to escape the Java sandbox and execute arbitrary code via unspecified vectors related to the security manager. This is part of a broader set of vulnerabilities addressed in Oracle's February 2015 Critical Patch Update.
Recommendations For IBM SDK, Java Technology Edition version 5.0, update to SR16-FP9 or later. For IBM SDK, Java Technology Edition version 6, update to SR16-FP3 or later. For IBM SDK, Java Technology Edition version 6R1, update to SR8-FP3 or later. For IBM SDK, Java Technology Edition version 7, update to SR8-FP10 or later. For IBM SDK, Java Technology Edition version 7R1, update to SR2-FP10 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2014-8891
RHSA-2015:0133
RHSA-2015:0134
RHSA-2015:0135
RHSA-2015:0136
RHSA-2015:0263
RHSA-2015:0264
RHSA-2015_0133
RHSA-2015_0135
RHSA-2015_0136
SUSE-SU-2015:0304-1
SUSE-SU-2015:0306-1
SUSE-SU-2015_0304-1
SUSE-SU-2015_0306-1
SUSE-SU-2015_0343-1
SUSE-SU-2015_0344-1
SUSE-SU-2015_0345-1
SUSE-SU-2015_0376-1
SUSE-SU-2015_0392-1

Affected Products

Ibm Aix
Ibm Sdk
Red Hat
Suse