CVE-2015-5006: Infoleak
An information leak flaw was found in the IBM JDK Java Security Components. Upstream security bulletin describes the issue as:
IBM Java Security Components could allow an attacker with physical access to the system to obtain sensitive information from the Kerberos Credential Cache.
References:
http://www-01.ibm.com/support/docview.wss?uid=swg21969225 http://www.ibm.com/developerworks/java/jdk/alerts/#IBMSecurityUpdateNovember2015
Other sources
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR2, 7 R1 before SR3 FP20, 7 before SR9 FP20, 6 R1 before SR8 FP15, and 6 before SR16 FP15 allow physically proximate attackers to obtain sensitive information by reading the Kerberos Credential Cache.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5006?
CVE-2015-5006 has been classified as a medium severity vulnerability due to its ability to allow local attackers to access sensitive information.
How do I fix CVE-2015-5006?
To fix CVE-2015-5006, upgrade to an IBM SDK version that is patched beyond the vulnerable releases mentioned in the CVE description.
What type of attack does CVE-2015-5006 facilitate?
CVE-2015-5006 facilitates a local information leak attack that enables attackers to read the Kerberos Credential Cache.
Which IBM SDK versions are affected by CVE-2015-5006?
IBM SDK versions 8 before SR2, 7 R1 before SR3 FP20, 6 R1 before SR8 FP15, and older versions are affected by CVE-2015-5006.
Who is potentially impacted by CVE-2015-5006?
Physically proximate attackers with access to the affected systems may exploit CVE-2015-5006 to obtain sensitive information.