« Volver al listado

CVE-2015-1914

Estado: ModificadaMedia (5)—

IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to bypass "permission checks" and obtain sensitive information via vectors related to the Java Virtual Machine.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-1914",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": true,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@us.ibm.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2015-07-02T21:59:01.377",
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00013.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2015-1006.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2015-1007.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2015-1020.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2015-1021.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2015-1091.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IV72245",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IV72246",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21883640",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/74645",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00013.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2015-1006.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2015-1007.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2015-1020.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2015-1021.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2015-1091.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IV72245",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IV72246",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21883640",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/74645",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to bypass \"permission checks\" and obtain sensitive information via vectors related to the Java Virtual Machine."
    },
    {
      "lang": "es",
      "value": "IBM Java 7 R1 anterior a SR3, 7 anterior a SR9, 6 R1 anterior a SR8 FP4, 6 anterior a SR16 FP4, y 5.0 anterior a SR16 FP10 permite a atacantes remotos evadir 'comprobaciones de permisos' y obtener información sensible a través de vectores relacionados con Java Virtual Machine."
    }
  ],
  "lastModified": "2026-06-17T00:23:13.263",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ibm:java:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D291505-B2CB-48F6-B4B9-8343DB71B4A2",
              "versionEndExcluding": "5.0.16.10",
              "versionStartIncluding": "5.0.0.0"
            },
            {
              "criteria": "cpe:2.3:a:ibm:java:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "34A916D0-0419-47B4-91D7-3E1E74233DEC",
              "versionEndExcluding": "6.0.16.4",
              "versionStartIncluding": "6.0.0.0"
            },
            {
              "criteria": "cpe:2.3:a:ibm:java:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FE2C442C-B649-4BEE-A228-467597CCA5F7",
              "versionEndExcluding": "6.1.8.4",
              "versionStartIncluding": "6.1.0.0"
            },
            {
              "criteria": "cpe:2.3:a:ibm:java:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2A22DE1A-87C0-42EE-85ED-368F168D4DAF",
              "versionEndExcluding": "7.0.9.0",
              "versionStartIncluding": "7.0.0.0"
            },
            {
              "criteria": "cpe:2.3:a:ibm:java:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A058B1EB-3B24-430C-A278-7ABF45262756",
              "versionEndExcluding": "7.1.3.0",
              "versionStartIncluding": "7.1.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@us.ibm.com"
}