9.1

CVE-2015-5041

The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote attackers to obtain sensitive information or inject data by invoking non-public interface methods.

Data is provided by the National Vulnerability Database (NVD)
IbmJava Sdk SwEditiontechnology Version >= 6.0.0.0 < 6.0.16.20
IbmJava Sdk SwEditiontechnology Version >= 6.1.0.0 < 6.1.8.20
IbmJava Sdk SwEditiontechnology Version >= 7.0.0.0 < 7.0.9.30
IbmJava Sdk SwEditiontechnology Version >= 7.1.0.0 < 7.1.3.30
SuseLinux Enterprise Server Version11 Updatesp2 SwEditionltss
SuseLinux Enterprise Server Version11 Updatesp4
SuseLinux Enterprise Server Version12 Updatesp1
IbmWebsphere Application Server Version <= 3.0.9.20
RedhatSatellite Version5.6
RedhatSatellite Version5.7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.89% 0.746
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.