CVE-2015-5006

low
Published 2015-12-07 · Modified 2026-05-06
CVSS v3
CVSS v2
2.1
VIR risk
2.1

Description

IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR2, 7 R1 before SR3 FP20, 7 before SR9 FP20, 6 R1 before SR8 FP15, and 6 before SR16 FP15 allow physically proximate attackers to obtain sensitive information by reading the Kerberos Credential Cache.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21969225

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg1IV78316

OS impact

OSVersionStatusFixed in
suse suse11affected
suse suse12affected
redhat rhel5.0affected
redhat rhel6.0affected
redhat rhel7.0affected

Application impact

VendorProductVersionsFixed
ibm ibmjava_2_sdk{"startIncluding":"5.0.0.0","endIncluding":"5.0.16.13"}
ibm ibmjava_sdk{"startIncluding":"6.0.0.0","endExcluding":"6.0.16.15"}6.0.16.15
redhat redhatsatellite5.6
redhat redhatsatellite5.7

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.