CVE-2015-5041

CRITICAL

IBM Java SDK 6.0.0.0-6.0.16.19, 6 R1 < SR8 FP20, 7 < SR9 FP30, 7 R1 < SR3 FP30 - Sensitive Information Exposure

Title source: llm
STIX 2.1

Description

The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote attackers to obtain sensitive information or inject data by invoking non-public interface methods.

References (8)

Core 8
Core References
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00028.html
Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IV72872
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00031.html
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2016:1430
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00026.html
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21974194
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/82451
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00032.html

Scores

CVSS v3 9.1
EPSS 0.0089
EPSS Percentile 75.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-200
Status published
Products (9)
ibm/java_sdk 6.0.0.0 - 6.0.16.20
ibm/websphere_application_server < 3.0.9.20
redhat/satellite 5.6
redhat/satellite 5.7
suse/linux_enterprise_server 11 sp2 (2 CPE variants)
suse/linux_enterprise_server 12 sp1
suse/linux_enterprise_software_development_kit 11 sp4
suse/linux_enterprise_software_development_kit 12 (2 CPE variants)
suse/suse_linux_enterprise_server 12
Published Jun 06, 2016
Tracked Since Feb 18, 2026