JDK: local disclosure of kerberos credentials cache
Published Dec 7, 2015
2.1
LOWCVSS 2.0
EPSS 0.48%
Description
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR2, 7 R1 before SR3 FP20, 7 before SR9 FP20, 6 R1 before SR8 FP15, and 6 before SR16 FP15 allow physically proximate attackers to obtain sensitive information by reading the Kerberos Credential Cache.
Affected products
No data.
Configuration 1
- ≥ 5.0.0.0 · ≤ 5.0.16.13
- ≥ 6.0.0.0 · < 6.0.16.15
- ≥ 6.1.0.0. · < 6.1.8.15
- ≥ 7.0.0.0 · < 7.0.9.20
- ≥ 7.1.0.0 · < 7.1.3.20
- ≥ 8.0.0.0 · < 8.0.2.0
Configuration 2
- 5.6
- 5.7
- 5.0
- 6.0
- 7.0
- 5.0
- 6.0
- 7.0
- 6.7
- 7.2
- 7.3
- 7.4
- 7.5
- 5.0
- 6.0
- 7.0
Configuration 3
- 11
- 11
- 11
- 11
- 12
- 11
- 11
- 12
No data.
Red Hat Enterprise Linux 5 Supplementary
java-1.6.0-ibm-1:1.6.0.16.15-1jpp.1.el5
Fixed · RHSA-2015:2508
Red Hat Enterprise Linux 5 Supplementary
java-1.7.0-ibm-1:1.7.0.9.20-1jpp.1.el5
Fixed · RHSA-2015:2507
Red Hat Enterprise Linux 6 Supplementary
java-1.6.0-ibm-1:1.6.0.16.15-1jpp.1.el6_7
Fixed · RHSA-2015:2508
Red Hat Enterprise Linux 6 Supplementary
java-1.7.1-ibm-1:1.7.1.3.20-1jpp.1.el6_7
Fixed · RHSA-2015:2506
Red Hat Enterprise Linux 7 Supplementary
java-1.7.1-ibm-1:1.7.1.3.20-1jpp.1.el7
Fixed · RHSA-2015:2506
Red Hat Enterprise Linux 7 Supplementary
java-1.8.0-ibm-1:1.8.0.2.0-1jpp.1.el7
Fixed · RHSA-2015:2509
Red Hat Satellite 5.6
java-1.7.0-ibm-1:1.7.0.9.40-1jpp.1.el5
Fixed · RHSA-2016:1430
Red Hat Satellite 5.6
java-1.7.1-ibm-1:1.7.1.3.40-1jpp.1.el6_7
Fixed · RHSA-2016:1430
Red Hat Satellite 5.6
spacewalk-java-0:2.0.2-109.el5sat
Fixed · RHSA-2016:1430
Red Hat Satellite 5.7
java-1.7.1-ibm-1:1.7.1.3.40-1jpp.1.el6_7
Fixed · RHSA-2016:1430
Red Hat Satellite 5.7
spacewalk-java-0:2.3.8-146.el6sat
Fixed · RHSA-2016:1430
Red Hat Enterprise Linux 5
java-1.5.0-ibm
Will not fix
Red Hat Enterprise Linux 6
java-1.5.0-ibm
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 Supplementary | java-1.6.0-ibm-1:1.6.0.16.15-1jpp.1.el5 | Fixed | RHSA-2015:2508 |
| Red Hat Enterprise Linux 5 Supplementary | java-1.7.0-ibm-1:1.7.0.9.20-1jpp.1.el5 | Fixed | RHSA-2015:2507 |
| Red Hat Enterprise Linux 6 Supplementary | java-1.6.0-ibm-1:1.6.0.16.15-1jpp.1.el6_7 | Fixed | RHSA-2015:2508 |
| Red Hat Enterprise Linux 6 Supplementary | java-1.7.1-ibm-1:1.7.1.3.20-1jpp.1.el6_7 | Fixed | RHSA-2015:2506 |
| Red Hat Enterprise Linux 7 Supplementary | java-1.7.1-ibm-1:1.7.1.3.20-1jpp.1.el7 | Fixed | RHSA-2015:2506 |
| Red Hat Enterprise Linux 7 Supplementary | java-1.8.0-ibm-1:1.8.0.2.0-1jpp.1.el7 | Fixed | RHSA-2015:2509 |
| Red Hat Satellite 5.6 | java-1.7.0-ibm-1:1.7.0.9.40-1jpp.1.el5 | Fixed | RHSA-2016:1430 |
| Red Hat Satellite 5.6 | java-1.7.1-ibm-1:1.7.1.3.40-1jpp.1.el6_7 | Fixed | RHSA-2016:1430 |
| Red Hat Satellite 5.6 | spacewalk-java-0:2.0.2-109.el5sat | Fixed | RHSA-2016:1430 |
| Red Hat Satellite 5.7 | java-1.7.1-ibm-1:1.7.1.3.40-1jpp.1.el6_7 | Fixed | RHSA-2016:1430 |
| Red Hat Satellite 5.7 | spacewalk-java-0:2.3.8-146.el6sat | Fixed | RHSA-2016:1430 |
| Red Hat Enterprise Linux 5 | java-1.5.0-ibm | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | java-1.5.0-ibm | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (20)
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00001.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00003.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00006.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00014.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00005.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-2506.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-2507.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-2508.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-2509.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV78316 vendor-advisoryx_refsource_AIXAPARVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21969225 x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/bid/77645 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1034214 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2016:1430 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2015-5006 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1282379 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2015-5006
- https://www.cve.org/CVERecord?id=CVE-2015-5006
Change history (0)
No recorded changes yet.