CVE-2015-5006
published 2015-12-07CVE-2015-5006: IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR2, 7 R1 before SR3 FP20, 7 before SR9 FP20, 6 R1 before SR8 FP15, and 6 before SR16…
PriorityP47low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.48%
38.4th percentile
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR2, 7 R1 before SR3 FP20, 7 before SR9 FP20, 6 R1 before SR8 FP15, and 6 before SR16 FP15 allow physically proximate attackers to obtain sensitive information by reading the Kerberos Credential Cache.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | java_2_sdk | 5.0.0.0 – 5.0.16.13 | — |
| ibm | java_sdk | >= 6.0.0.0 < 6.0.16.15 | 6.0.16.15 |
| ibm | java_sdk | >= 6.1.0.0. < 6.1.8.15 | 6.1.8.15 |
| ibm | java_sdk | >= 7.0.0.0 < 7.0.9.20 | 7.0.9.20 |
| ibm | java_sdk | >= 7.1.0.0 < 7.1.3.20 | 7.1.3.20 |
| ibm | java_sdk | >= 8.0.0.0 < 8.0.2.0 | 8.0.2.0 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | satellite | — | — |
| redhat | satellite | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rm84-76qf-3pxc: IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR2, 7 R1 before SR3 FP20, 7 before SR9 FP20, 6 R1 before SR8 FP15, and 6 be
ghsa_unreviewed·2022-05-14
CVE-2015-5006 [LOW] CWE-200 GHSA-rm84-76qf-3pxc: IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR2, 7 R1 before SR3 FP20, 7 before SR9 FP20, 6 R1 before SR8 FP15, and 6 be
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR2, 7 R1 before SR3 FP20, 7 before SR9 FP20, 6 R1 before SR8 FP15, and 6 before SR16 FP15 allow physically proximate attackers to obtain sensitive information by reading the Kerberos Credential Cache.
Red Hat
JDK: local disclosure of kerberos credentials cache
vendor_redhat·2015-11-13·CVSS 2.1
CVE-2015-5006 [LOW] JDK: local disclosure of kerberos credentials cache
JDK: local disclosure of kerberos credentials cache
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR2, 7 R1 before SR3 FP20, 7 before SR9 FP20, 6 R1 before SR8 FP15, and 6 before SR16 FP15 allow physically proximate attackers to obtain sensitive information by reading the Kerberos Credential Cache.
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 5) - Will not fix
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 6) - Will not fix
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2506.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2507.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2508.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2509.htmlhttp://www-01.ibm.com/support/docview.wss?uid=swg1IV78316http://www-01.ibm.com/support/docview.wss?uid=swg21969225http://www.securityfocus.com/bid/77645http://www.securitytracker.com/id/1034214https://access.redhat.com/errata/RHSA-2016:1430http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2506.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2507.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2508.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2509.htmlhttp://www-01.ibm.com/support/docview.wss?uid=swg1IV78316http://www-01.ibm.com/support/docview.wss?uid=swg21969225http://www.securityfocus.com/bid/77645http://www.securitytracker.com/id/1034214https://access.redhat.com/errata/RHSA-2016:1430
2015-12-07
Published