Where
-Infinity
0
Severity
10
AV:N/AC:L/Au:N/C:C/I:C/A:C

IBM JDK updates 7R1 SR2-FP10, 7 SR8-FP10, 6R1 SR8-FP3, 6 SR16-FP3 and 5.0 SR16-FP9 correct an unspecified vulnerability identified using CVE-2014-8891. Upstream has rated this issue with CVSSv2 score of 6.8 (no vector provided).

http://www.ibm.com/developerworks/java/jdk/alerts/#IBMSecurityUpdateFebruary2015

Further details of the issue should be made available via the following link:

http://www.ibm.com/support/docview.wss?uid=swg21695747

1 / 2
Source: Red Hat
First published (updated )
Severity
9.8
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. By sending specially-crafted data, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 236069.

1 / 2
First published (updated )
Severity
9.1
Infoleak
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

The following flaw was reported for IBM JDK:

A flaw in the IBM J9 JVM allows code to invoke non-public interface methods under certain circumstances. Untrusted code could potentially exploit this. This could lead to sensitive data being exposed to an attacker, or the attacker being able to inject bad data.

http://www-01.ibm.com/support/docview.wss?uid=swg21974193 http://www.ibm.com/developerworks/java/jdk/alerts/#IBMSecurityUpdateJanuary2016

This flaw could allow an untrusted Java application or applet to bypass certain Java sandbox restrictions.

Issue was fixed in IBM JDK 6 SR16-FP20, 7 SR9-FP30, 7R1 SR3-FP30, and 8 SR2-FP10.

1 / 2
Source: Red Hat
First published (updated )
Severity
8.1
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Adam Gowdiak (Security Explorations) reported that the fix for IBM JDK issue CVE-2013-5456 (bug 1027748), also known as "Issue 70", did not correctly address the problem. Applied fix only restricted access to the vulnerable package, rather then addressing the underlying problem of running untrusted code inside doPrivileged block.

Report:

http://seclists.org/fulldisclosure/2016/Apr/43

Write-up of the issue:

http://www.security-explorations.com/materials/SE-2012-01-IBM-5.pdf

Proof-of-concept code:

http://www.security-explorations.com/materials/se-2012-01-70.2.zip

1 / 2
Source: Red Hat
First published (updated )
Severity
8.1
Input Validation
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

It was reported that the IBM fix for the issue 67 from this document http://www.security-explorations.com/materials/SE-2012-01-IBM-2.pdf didn't address the problem properly.

References:

http://seclists.org/fulldisclosure/2016/Apr/3

Full report:

http://www.security-explorations.com/materials/SE-2012-01-IBM-4.pdf

1 / 2
Source: Red Hat
First published (updated )
Severity
8.1
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Under certain circumstances, a flaw in the J9 JVM (IBM SDK, Java Technology Edition 7.1 and 8.0) allows untrusted code running under a security manager to elevate its privileges.

External References:

https://exchange.xforce.ibmcloud.com/vulnerabilities/138823

1 / 2
Source: Red Hat
First published (updated )
Severity
7.8
AV:N/AC:L/Au:N/C:C/I:N/A:N

IBM JDK updates 7R1 SR2-FP10, 7 SR8-FP10, 6R1 SR8-FP3, 6 SR16-FP3 and 5.0 SR16-FP9 correct an unspecified vulnerability identified using CVE-2014-8892. Upstream has rated this issue with CVSSv2 score of 4.3 (no vector provided).

http://www.ibm.com/developerworks/java/jdk/alerts/#IBMSecurityUpdateFebruary2015

Further details of the issue should be made available via the following link:

http://www.ibm.com/support/docview.wss?uid=swg21695747

1 / 2
Source: Red Hat
First published (updated )
Severity
7.2
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

IBM SDK, Java Technology Edition Version 7.0.0.0 through 7.0.10.55, 7.1.0.0 through 7.1.4.55, and 8.0.0.0 through 8.0.6.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability in Microsoft Windows client. By placing a specially-crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 172618.

1 / 2
First published (updated )
Severity
6.8
Buffer Overflow
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

A buffer overflow flaw was fixed in IBM JDK 6 SR16-FP25, 7 SR9-FP40, 7R1 SR3-FP40, and 8 SR3:

CVEID: CVE-2016-0264 DESCRIPTION: A buffer overflow vulnerability in the IBM JVM facilitates arbitrary code execution under certain limited circumstances. CVSS Base Score: 5.6 CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)

http://www-01.ibm.com/support/docview.wss?uid=swg21980826

External Reference:

http://www.ibm.com/developerworks/java/jdk/alerts/#IBMSecurityUpdateApril2016

1 / 2
Source: Red Hat
First published (updated )
Severity
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows local users to obtain sensitive information by reading a file.

First published (updated )
Severity
2.1
Infoleak
AV:L/AC:L/Au:N/C:P/I:N/A:N

An information leak flaw was found in the IBM JDK Java Security Components. Upstream security bulletin describes the issue as:

IBM Java Security Components could allow an attacker with physical access to the system to obtain sensitive information from the Kerberos Credential Cache.

References:

http://www-01.ibm.com/support/docview.wss?uid=swg21969225 http://www.ibm.com/developerworks/java/jdk/alerts/#IBMSecurityUpdateNovember2015

1 / 2
Source: Red Hat
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203