CVE-2015-1931

Advisory lineage Upstream: 0 Downstream: 10
Modified
Published: 23 Jan 2020, 18:42
Last modified:06 Aug 2024, 05:02

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.05% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 Jan 2020, 18:42
Published
Vulnerability first disclosed
06 Aug 2024, 05:02
Last Modified
Vulnerability information updated

Description

IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows local users to obtain sensitive information by reading a file.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.05% Percentile: 17%

Techniques & Countermeasures

  • CWE-312Cleartext Storage of Sensitive Information

    The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Systems

  • ibmjava_sdk

    ≥ 5.0.0.0, < 5.0.16.13 | ≥ 6.0.0.0, < 6.0.16.7 | ≥ 6.1.0.0, < 6.1.8.7 | ≥ 7.0.0.0, < 7.0.9.10 | ≥ 7.1.0.0, < 7.1.3.10 | ≥ 8.0.0.0, < 8.0.1.10

  • redhatenterprise_linux_desktop

    5.0 | 6.0 | 7.0

  • redhatenterprise_linux_eus

    6.7 | 7.1 | 7.2 | 7.3 | 7.4 | 7.5

  • redhatenterprise_linux_server

    5.0 | 6.0 | 7.0

  • redhatenterprise_linux_workstation

    5.0 | 6.0 | 7.0

  • redhatsatellite

    5.6 | 5.7

  • suselinux_enterprise_server

    11:sp1 | 11:sp2 | 11:sp3 | 11:sp4

  • suselinux_enterprise_software_development_kit

    11:sp3 | 11:sp4

References (10)