CVE-2015-1931
published 2022-09-29CVE-2015-1931: IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.22%
12.7th percentile
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows local users to obtain sensitive information by reading a file.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | java_sdk | >= 5.0.0.0 < 5.0.16.13 | 5.0.16.13 |
| ibm | java_sdk | >= 6.0.0.0 < 6.0.16.7 | 6.0.16.7 |
| ibm | java_sdk | >= 6.1.0.0 < 6.1.8.7 | 6.1.8.7 |
| ibm | java_sdk | >= 7.0.0.0 < 7.0.9.10 | 7.0.9.10 |
| ibm | java_sdk | >= 7.1.0.0 < 7.1.3.10 | 7.1.3.10 |
| ibm | java_sdk | >= 8.0.0.0 < 8.0.1.10 | 8.0.1.10 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | satellite | — | — |
| redhat | satellite | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-43cg-c28c-82hq: IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 be
ghsa_unreviewed·2022-09-30
CVE-2015-1931 [MEDIUM] CWE-312 GHSA-43cg-c28c-82hq: IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 be
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows local users to obtain sensitive information by reading a file.
Red Hat
JDK: plain text data stored in memory dumps
vendor_redhat·2015-07-20·CVSS 5.5
CVE-2015-1931 [MEDIUM] JDK: plain text data stored in memory dumps
JDK: plain text data stored in memory dumps
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows local users to obtain sensitive information by reading a file.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00051.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00014.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1485.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1486.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1488.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1544.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1604.htmlhttp://www-01.ibm.com/support/docview.wss?uid=swg1IV75182http://www-01.ibm.com/support/docview.wss?uid=swg21962302http://www.securityfocus.com/bid/75985http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00051.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00014.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1485.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1486.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1488.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1544.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1604.htmlhttp://www-01.ibm.com/support/docview.wss?uid=swg1IV75182http://www-01.ibm.com/support/docview.wss?uid=swg21962302http://www.securityfocus.com/bid/75985
2022-09-29
Published