PT-2015-5503 · Ibm+2 · Ibm Java+3
Published
2015-05-13
·
Updated
2019-06-13
·
CVE-2015-1914
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Java versions prior to 7 R1 SR3
IBM Java versions prior to 7 SR9
IBM Java 6 R1 versions prior to SR8 FP4
IBM Java 6 versions prior to SR16 FP4
IBM Java 5.0 versions prior to SR16 FP10
Description
The issue allows remote attackers to bypass permission checks and obtain sensitive information via vectors related to the Java Virtual Machine. Additionally, a vulnerability in IBM SSL/TLS implementations could allow a remote attacker to downgrade the security of certain SSL/TLS connections, facilitating brute-force decryption of TLS/SSL traffic between vulnerable clients and servers using man-in-the-middle techniques.
Recommendations
For IBM Java 7 R1, update to SR3 or later.
For IBM Java 7, update to SR9 or later.
For IBM Java 6 R1, update to SR8 FP4 or later.
For IBM Java 6, update to SR16 FP4 or later.
For IBM Java 5.0, update to SR16 FP10 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Aix
Ibm Java
Red Hat
Suse