IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to bypass "permission checks" and obtain sensitive information via vectors related to the Java Virtual Machine.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:26
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00013.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.html - Mailing List, Third Party Advisory | |
References | () http://rhn.redhat.com/errata/RHSA-2015-1006.html - Third Party Advisory | |
References | () http://rhn.redhat.com/errata/RHSA-2015-1007.html - Third Party Advisory | |
References | () http://rhn.redhat.com/errata/RHSA-2015-1020.html - Third Party Advisory | |
References | () http://rhn.redhat.com/errata/RHSA-2015-1021.html - Third Party Advisory | |
References | () http://rhn.redhat.com/errata/RHSA-2015-1091.html - Third Party Advisory | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg1IV72245 - Vendor Advisory | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg1IV72246 - Vendor Advisory | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg21883640 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/74645 - Third Party Advisory, VDB Entry |
Information
Published : 2015-07-02 21:59
Updated : 2024-11-21 02:26
NVD link : CVE-2015-1914
Mitre link : CVE-2015-1914
CVE.ORG link : CVE-2015-1914
JSON object : View
Products Affected
ibm
- java
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor