IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows local users to obtain sensitive information by reading a file.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 02:26
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00051.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00014.html - Mailing List, Third Party Advisory | |
References | () http://rhn.redhat.com/errata/RHSA-2015-1485.html - Third Party Advisory | |
References | () http://rhn.redhat.com/errata/RHSA-2015-1486.html - Third Party Advisory | |
References | () http://rhn.redhat.com/errata/RHSA-2015-1488.html - Third Party Advisory | |
References | () http://rhn.redhat.com/errata/RHSA-2015-1544.html - Third Party Advisory | |
References | () http://rhn.redhat.com/errata/RHSA-2015-1604.html - Third Party Advisory | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg1IV75182 - Vendor Advisory | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg21962302 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/75985 - Broken Link |
Information
Published : 2022-09-29 03:15
Updated : 2024-11-21 02:26
NVD link : CVE-2015-1931
Mitre link : CVE-2015-1931
CVE.ORG link : CVE-2015-1931
JSON object : View
Products Affected
redhat
- enterprise_linux_server
- enterprise_linux_desktop
- satellite
- enterprise_linux_eus
- enterprise_linux_workstation
suse
- linux_enterprise_software_development_kit
- linux_enterprise_server
ibm
- java_sdk
CWE
CWE-312
Cleartext Storage of Sensitive Information