CVE-2015-1914

Advisory lineage Upstream: 0 Downstream: 7
Modified
Published: 02 Jul 2015, 21:16
Last modified:06 Aug 2024, 04:54

Vulnerability Summary

Overall Risk (default)
low
20/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
0.21% LOW
0% probability +0.06%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

02 Jul 2015, 21:16
Published
Vulnerability first disclosed
06 Aug 2024, 04:54
Last Modified
Vulnerability information updated

Description

IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to bypass "permission checks" and obtain sensitive information via vectors related to the Java Virtual Machine.

CVSS Metrics

  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 0.21% Percentile: 44%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • ibmjava

    ≥ 5.0.0.0, < 5.0.16.10 | ≥ 6.0.0.0, < 6.0.16.4 | ≥ 6.1.0.0, < 6.1.8.4 | ≥ 7.0.0.0, < 7.0.9.0 | ≥ 7.1.0.0, < 7.1.3.0

References (14)