IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows local users to obtain sensitive information by reading a file.
References
Link | Resource |
---|---|
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00051.html | Mailing List Third Party Advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg21962302 | Vendor Advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1IV75182 | Vendor Advisory |
http://rhn.redhat.com/errata/RHSA-2015-1604.html | Third Party Advisory |
http://rhn.redhat.com/errata/RHSA-2015-1486.html | Third Party Advisory |
http://rhn.redhat.com/errata/RHSA-2015-1488.html | Third Party Advisory |
http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00014.html | Mailing List Third Party Advisory |
http://rhn.redhat.com/errata/RHSA-2015-1485.html | Third Party Advisory |
http://rhn.redhat.com/errata/RHSA-2015-1544.html | Third Party Advisory |
http://www.securityfocus.com/bid/75985 | Broken Link |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2022-09-28 20:15
Updated : 2022-09-29 20:04
NVD link : CVE-2015-1931
Mitre link : CVE-2015-1931
JSON object : View
CWE
CWE-312
Cleartext Storage of Sensitive Information
Products Affected
ibm
- java_sdk
redhat
- enterprise_linux_desktop
- enterprise_linux_workstation
- satellite
- enterprise_linux_server
- enterprise_linux_eus
suse
- linux_enterprise_software_development_kit
- linux_enterprise_server