CVE-2015-1914
published 2015-07-02CVE-2015-1914: IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to bypass "permission checks"…
PriorityP429medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
4.04%
89.5th percentile
IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to bypass "permission checks" and obtain sensitive information via vectors related to the Java Virtual Machine.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | java | >= 5.0.0.0 < 5.0.16.10 | 5.0.16.10 |
| ibm | java | >= 6.0.0.0 < 6.0.16.4 | 6.0.16.4 |
| ibm | java | >= 6.1.0.0 < 6.1.8.4 | 6.1.8.4 |
| ibm | java | >= 7.0.0.0 < 7.0.9.0 | 7.0.9.0 |
| ibm | java | >= 7.1.0.0 < 7.1.3.0 | 7.1.3.0 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JDK: unspecified partial Java sandbox restrictions bypass
vendor_redhat·2015-05-06·CVSS 5.0
CVE-2015-1914 [MEDIUM] JDK: unspecified partial Java sandbox restrictions bypass
JDK: unspecified partial Java sandbox restrictions bypass
IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to bypass "permission checks" and obtain sensitive information via vectors related to the Java Virtual Machine.
GHSA
GHSA-f6r5-5pp4-r7jw: IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5
ghsa_unreviewed·2022-05-14
CVE-2015-1914 [MEDIUM] CWE-200 GHSA-f6r5-5pp4-r7jw: IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5
IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to bypass "permission checks" and obtain sensitive information via vectors related to the Java Virtual Machine.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1006.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1007.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1020.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1021.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1091.htmlhttp://www-01.ibm.com/support/docview.wss?uid=swg1IV72245http://www-01.ibm.com/support/docview.wss?uid=swg1IV72246http://www-01.ibm.com/support/docview.wss?uid=swg21883640http://www.securityfocus.com/bid/74645http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1006.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1007.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1020.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1021.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1091.htmlhttp://www-01.ibm.com/support/docview.wss?uid=swg1IV72245http://www-01.ibm.com/support/docview.wss?uid=swg1IV72246http://www-01.ibm.com/support/docview.wss?uid=swg21883640http://www.securityfocus.com/bid/74645
2015-07-02
Published