CVE-2015-1931
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows…
Does this matter?
Lower severity and a low EPSS score (0.22%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows local users to obtain sensitive information by reading a file.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.22% probability · 13th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-312
- Affected
- ibm/java sdk · suse/linux enterprise server · suse/linux enterprise software development kit · redhat/satellite · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux workstation
- Source
- psirt@us.ibm.com
References
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00051.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00014.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1485.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1486.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1488.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1544.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1604.htmlThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV75182Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21962302Vendor Advisory
- http://www.securityfocus.com/bid/75985Broken Link
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00051.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00014.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1485.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1486.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1488.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1544.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1604.htmlThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV75182Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21962302Vendor Advisory
- http://www.securityfocus.com/bid/75985Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.