(IBM Issues Fix for IBM AIX) IBM Java Flaw Lets Local Users Obtain Sensitive Kerberos Credentials Information on the Target System
|
SecurityTracker Alert ID: 1034387 |
SecurityTracker URL: http://securitytracker.com/id/1034387
|
CVE Reference:
CVE-2015-5006
(Links to External Site)
|
Date: Dec 11 2015
|
Impact:
Disclosure of authentication information
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 5.0, 6.0, 6.1, 7.0, 7.1, 8.0
|
Description:
A vulnerability was reported in IBM Java. A physically local user can obtain sensitive information from the Kerberos Credential Cache.
No details were provided.
|
Impact:
A physically local user can obtain sensitive information from the Kerberos Credential Cache.
|
Solution:
IBM has issued a fix for IBM AIX.
The IBM advisory is available at:
https://aix.software.ibm.com/aix/efixes/security/java_oct2015_advisory.asc
|
Vendor URL: aix.software.ibm.com/aix/efixes/security/java_oct2015_advisory.asc (Links to External Site)
|
Cause:
Access control error
|
Underlying OS: UNIX (AIX)
|
Underlying OS Comments: 5.3, 6.1, 7.1, 7.2
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
|
[Original Message Not Available for Viewing]
|
|