JDK: plain text data stored in memory dumps
Published Jan 23, 2020
5.5
MEDIUMCVSS 3.1
EPSS 0.22%
Description
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows local users to obtain sensitive information by reading a file.
Affected products
No data.
Configuration 1
Configuration 2
- 11
- 11
- 11
- 11
- 11
- 11
- 11
Configuration 3
- 5.6
- 5.7
- 5.0
- 6.0
- 7.0
- 6.7
- 7.1
- 7.2
- 7.3
- 7.4
- 7.5
- 5.0
- 6.0
- 7.0
- 5.0
- 6.0
- 7.0
No data.
Red Hat Enterprise Linux 5 Supplementary
java-1.5.0-ibm-1:1.5.0.16.13-1jpp.3.el5
Fixed · RHSA-2015:1544
Red Hat Enterprise Linux 5 Supplementary
java-1.6.0-ibm-1:1.6.0.16.7-1jpp.1.el5
Fixed · RHSA-2015:1486
Red Hat Enterprise Linux 5 Supplementary
java-1.7.0-ibm-1:1.7.0.9.10-1jpp.2.el5
Fixed · RHSA-2015:1488
Red Hat Enterprise Linux 6 Supplementary
java-1.5.0-ibm-1:1.5.0.16.13-1jpp.3.el6_7
Fixed · RHSA-2015:1544
Red Hat Enterprise Linux 6 Supplementary
java-1.6.0-ibm-1:1.6.0.16.7-1jpp.1.el6_7
Fixed · RHSA-2015:1486
Red Hat Enterprise Linux 6 Supplementary
java-1.7.1-ibm-1:1.7.1.3.10-1jpp.3.el6_7
Fixed · RHSA-2015:1485
Red Hat Satellite 5.6
java-1.6.0-ibm-1:1.6.0.16.7-1jpp.1.el5
Fixed · RHSA-2015:1604
Red Hat Satellite 5.7
java-1.6.0-ibm-1:1.6.0.16.7-1jpp.1.el6_7
Fixed · RHSA-2015:1604
Supplementary for Red Hat Enterprise Linux 7
java-1.7.1-ibm-1:1.7.1.3.10-1jpp.1.ael7b_1
Fixed · RHSA-2015:1485
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 Supplementary | java-1.5.0-ibm-1:1.5.0.16.13-1jpp.3.el5 | Fixed | RHSA-2015:1544 |
| Red Hat Enterprise Linux 5 Supplementary | java-1.6.0-ibm-1:1.6.0.16.7-1jpp.1.el5 | Fixed | RHSA-2015:1486 |
| Red Hat Enterprise Linux 5 Supplementary | java-1.7.0-ibm-1:1.7.0.9.10-1jpp.2.el5 | Fixed | RHSA-2015:1488 |
| Red Hat Enterprise Linux 6 Supplementary | java-1.5.0-ibm-1:1.5.0.16.13-1jpp.3.el6_7 | Fixed | RHSA-2015:1544 |
| Red Hat Enterprise Linux 6 Supplementary | java-1.6.0-ibm-1:1.6.0.16.7-1jpp.1.el6_7 | Fixed | RHSA-2015:1486 |
| Red Hat Enterprise Linux 6 Supplementary | java-1.7.1-ibm-1:1.7.1.3.10-1jpp.3.el6_7 | Fixed | RHSA-2015:1485 |
| Red Hat Satellite 5.6 | java-1.6.0-ibm-1:1.6.0.16.7-1jpp.1.el5 | Fixed | RHSA-2015:1604 |
| Red Hat Satellite 5.7 | java-1.6.0-ibm-1:1.6.0.16.7-1jpp.1.el6_7 | Fixed | RHSA-2015:1604 |
| Supplementary for Red Hat Enterprise Linux 7 | java-1.7.1-ibm-1:1.7.1.3.10-1jpp.1.ael7b_1 | Fixed | RHSA-2015:1485 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.22% (0.00222) | 11.57th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.23% (0.00231) | 13.65th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.04% (0.00043) | 10.08th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00042) | 5.07th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.28% (0.01282) | 68.34th | v2 (v2022.01.01) |
| Feb 22, 2023 | 1.28% (0.01282) | 68.05th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.28% (0.01282) | 65.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.28% (0.01282) | 41.72th | v2 (v2022.01.01) |
References (14)
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00051.html x_refsource_MISCMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00014.html x_refsource_MISCMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1485.html x_refsource_MISCThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1486.html x_refsource_MISCThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1488.html x_refsource_MISCThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1544.html x_refsource_MISCThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1604.html x_refsource_MISCThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV75182 x_refsource_MISCVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21962302 x_refsource_MISCVendor Advisory
- http://www.securityfocus.com/bid/75985 x_refsource_MISCBroken Link
- https://access.redhat.com/security/cve/CVE-2015-1931 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1244828 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2015-1931
- https://www.cve.org/CVERecord?id=CVE-2015-1931
Change history (0)
No recorded changes yet.