First published: Mon Nov 16 2015(Updated: )
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR2, 7 R1 before SR3 FP20, 7 before SR9 FP20, 6 R1 before SR8 FP15, and 6 before SR16 FP15 allow physically proximate attackers to obtain sensitive information by reading the Kerberos Credential Cache.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM SDK | >=5.0.0.0<=5.0.16.13 | |
IBM SDK | >=6.0.0.0<6.0.16.15 | |
IBM SDK | >=6.1.0.0.<6.1.8.15 | |
IBM SDK | >=7.0.0.0<7.0.9.20 | |
IBM SDK | >=7.1.0.0<7.1.3.20 | |
IBM SDK | >=8.0.0.0<8.0.2.0 | |
redhat satellite | =5.6 | |
redhat satellite | =5.7 | |
redhat enterprise Linux desktop | =5.0 | |
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux desktop | =7.0 | |
redhat enterprise Linux server | =5.0 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux server | =7.0 | |
redhat enterprise Linux server eus | =6.7 | |
redhat enterprise Linux server eus | =7.2 | |
redhat enterprise Linux server eus | =7.3 | |
redhat enterprise Linux server eus | =7.4 | |
redhat enterprise Linux server eus | =7.5 | |
redhat enterprise Linux workstation | =5.0 | |
redhat enterprise Linux workstation | =6.0 | |
redhat enterprise Linux workstation | =7.0 | |
SUSE Linux Enterprise Server | =11-sp2 | |
SUSE Linux Enterprise Server | =11-sp3 | |
suse linux enterprise server vmware | =11-sp3 | |
SUSE Linux Enterprise Server | =11-sp4 | |
SUSE Linux Enterprise Server | =12 | |
SUSE Linux Enterprise Software Development Kit | =11-sp3 | |
SUSE Linux Enterprise Software Development Kit | =11-sp4 | |
SUSE Linux Enterprise Software Development Kit | =12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5006 has been classified as a medium severity vulnerability due to its ability to allow local attackers to access sensitive information.
To fix CVE-2015-5006, upgrade to an IBM SDK version that is patched beyond the vulnerable releases mentioned in the CVE description.
CVE-2015-5006 facilitates a local information leak attack that enables attackers to read the Kerberos Credential Cache.
IBM SDK versions 8 before SR2, 7 R1 before SR3 FP20, 6 R1 before SR8 FP15, and older versions are affected by CVE-2015-5006.
Physically proximate attackers with access to the affected systems may exploit CVE-2015-5006 to obtain sensitive information.