PT-2015-4518 · Ibm+2 · Ibm Java 7+8

Published

2015-05-13

·

Updated

2026-05-27

·

CVE-2015-0192

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Java versions prior to 8 SR1 IBM Java 7 R1 versions prior to SR2 FP11 IBM Java 7 versions prior to SR9 IBM Java 6 R1 versions prior to SR8 FP4 IBM Java 6 versions prior to SR16 FP4 IBM Java 5.0 versions prior to SR16 FP10
Description The issue allows remote attackers to gain privileges via unknown vectors related to the Java Virtual Machine. Additionally, a vulnerability in IBM SSL/TLS implementations could allow a remote attacker to downgrade the security of certain SSL/TLS connections, facilitating brute-force decryption of TLS/SSL traffic between vulnerable clients and servers using man-in-the-middle techniques. This is also known as the FREAK attack.
Recommendations For IBM Java 8, update to SR1 or later. For IBM Java 7 R1, update to SR2 FP11 or later. For IBM Java 7, update to SR9 or later. For IBM Java 6 R1, update to SR8 FP4 or later. For IBM Java 6, update to SR16 FP4 or later. For IBM Java 5.0, update to SR16 FP10 or later.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2015-0192
RHSA-2015:1006
RHSA-2015:1007
RHSA-2015:1020
RHSA-2015:1021
RHSA-2015:1091
RHSA-2015_1006
RHSA-2015_1020
RHSA-2015_1021
SUSE-SU-2015:1073-1
SUSE-SU-2015:1161-1
SUSE-SU-2015:1375-1
SUSE-SU-2015_1375-1

Affected Products

Ibm Aix
Ibm Java 5.0
Ibm Java 6
Ibm Java 6 R1
Ibm Java 7
Ibm Java 7 R1
Ibm Java 8
Red Hat
Suse