PT-2015-6750 · Ibm+2 · Ibm Sdk+3

Published

2015-11-23

·

Updated

2019-06-19

·

CVE-2015-5006

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Java Security Components in IBM SDK, Java Technology Edition versions 8 before SR2 IBM Java Security Components in IBM SDK, Java Technology Edition versions 7 R1 before SR3 FP20 IBM Java Security Components in IBM SDK, Java Technology Edition versions 7 before SR9 FP20 IBM Java Security Components in IBM SDK, Java Technology Edition versions 6 R1 before SR8 FP15 IBM Java Security Components in IBM SDK, Java Technology Edition versions 6 before SR16 FP15
Description The issue allows physically proximate attackers to obtain sensitive information by reading the Kerberos Credential Cache. An attacker with physical access to the system could exploit this to gain access to sensitive information.
Recommendations For IBM Java Security Components in IBM SDK, Java Technology Edition version 8 before SR2, update to SR2 or later. For IBM Java Security Components in IBM SDK, Java Technology Edition version 7 R1 before SR3 FP20, update to SR3 FP20 or later. For IBM Java Security Components in IBM SDK, Java Technology Edition version 7 before SR9 FP20, update to SR9 FP20 or later. For IBM Java Security Components in IBM SDK, Java Technology Edition version 6 R1 before SR8 FP15, update to SR8 FP15 or later. For IBM Java Security Components in IBM SDK, Java Technology Edition version 6 before SR16 FP15, update to SR16 FP15 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-5006
RHSA-2015:2506
RHSA-2015:2507
RHSA-2015:2508
RHSA-2015:2509
RHSA-2015_2506
RHSA-2015_2508
RHSA-2015_2509
RHSA-2016:1430
SUSE-SU-2015:2166-1
SUSE-SU-2015:2168-1
SUSE-SU-2015:2168-2
SUSE-SU-2015:2182-1
SUSE-SU-2015:2192-1
SUSE-SU-2015:2216-1
SUSE-SU-2015:2268-1

Affected Products

Ibm Aix
Ibm Sdk
Red Hat
Suse