← Vulnerability feed

Vulnerability record · CVE-2015-1914 · published 2 July 2015

CVE-2015-1914: Ibm java information exposure vulnerability

Ibm · Java

IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to bypass "permission checks" and obtain sensitive information via vectors related to the Java Virtual Machine.

5.0 CVSS 2.0 Medium EPSS 4.0% · top 9.7% CWE-200 · Information exposure
5.0CVSS 2.0 base score
4.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
28References
17 Jun 2026Last modified by NVD

Description

IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to bypass "permission checks" and obtain sensitive information via vectors related to the Java Virtual Machine.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00013.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.html Mailing ListThird Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1006.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1007.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1020.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1021.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1091.html Third Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg1IV72245 Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg1IV72246 Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21883640 Vendor Advisory
http://www.securityfocus.com/bid/74645 Third Party AdvisoryVDB Entry
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00013.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.html Mailing ListThird Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1006.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1007.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1020.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1021.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1091.html Third Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg1IV72245 Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg1IV72246 Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21883640 Vendor Advisory
http://www.securityfocus.com/bid/74645 Third Party AdvisoryVDB Entry

Track CVE-2015-1914 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-0485Ibm java vulnerabilityUnspecified vulnerability in IBM Java SDK 7 before SR4-FP1, 6 before SR13-FP1, 5.0 before SR16-FP1, and 1.4.2 before SR13-FP16 has unknown impact and…EPSS 2.4%9.8CVE-2015-0192Ibm java improper privilege management vulnerabilityUnspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 F…EPSS 4.0%9.3CVE-2013-5456Ibm java vulnerabilityThe com.ibm.rmi.io.SunSerializableFactory class in IBM Java SDK 7.0.0 before SR6 allows remote attackers to bypass a sandbox protection mechanism and…EPSS 6.0%9.3CVE-2013-5457Ibm java vulnerabilityUnspecified vulnerability in IBM Java SDK 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15 allows remote attackers to execute arbitrary code…EPSS 6.1%9.3CVE-2013-5458Ibm java vulnerabilityUnspecified vulnerability in IBM Java SDK 7.0.0 before SR6 allows remote attackers to execute arbitrary code via unspecified vectors.EPSS 5.4%9.3CVE-2013-3006Ibm java vulnerabilityUnspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 7 before 7 SR5 allows remote attackers to affect confidentiality, availab…EPSS 4.0%9.3CVE-2013-3007Ibm java vulnerabilityUnspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 6.0.1 before 6.0.1 SR6 and 7 before 7 SR5 allows remote attackers to affe…EPSS 4.0%9.3CVE-2013-3008Ibm java vulnerabilityUnspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 7 before 7 SR5 allows remote attackers to affect confidentiality, availab…EPSS 4.0%

Source: NIST National Vulnerability Database (record CVE-2015-1914), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.