PT-2015-4518 · Ibm+2 · Ibm Java 7+8

CVE-2015-0192

·

Publicado

2015-05-13

·

Atualizado

2026-05-27

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Java versions prior to 8 SR1 IBM Java 7 R1 versions prior to SR2 FP11 IBM Java 7 versions prior to SR9 IBM Java 6 R1 versions prior to SR8 FP4 IBM Java 6 versions prior to SR16 FP4 IBM Java 5.0 versions prior to SR16 FP10
Description The issue allows remote attackers to gain privileges via unknown vectors related to the Java Virtual Machine. Additionally, a vulnerability in IBM SSL/TLS implementations could allow a remote attacker to downgrade the security of certain SSL/TLS connections, facilitating brute-force decryption of TLS/SSL traffic between vulnerable clients and servers using man-in-the-middle techniques. This is also known as the FREAK attack.
Recommendations For IBM Java 8, update to SR1 or later. For IBM Java 7 R1, update to SR2 FP11 or later. For IBM Java 7, update to SR9 or later. For IBM Java 6 R1, update to SR8 FP4 or later. For IBM Java 6, update to SR16 FP4 or later. For IBM Java 5.0, update to SR16 FP10 or later.

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-0192
RHSA-2015:1006
RHSA-2015:1007
RHSA-2015:1020
RHSA-2015:1021
RHSA-2015:1091
RHSA-2015_1006
RHSA-2015_1020
RHSA-2015_1021
SUSE-SU-2015:1073-1
SUSE-SU-2015:1161-1
SUSE-SU-2015:1375-1
SUSE-SU-2015_1375-1

Produtos afetados

Ibm Aix
Ibm Java 5.0
Ibm Java 6
Ibm Java 6 R1
Ibm Java 7
Ibm Java 7 R1
Ibm Java 8
Red Hat
Suse