VYPR
Critical severity9.1NVD Advisory· Published Jun 6, 2016· Updated May 6, 2026

CVE-2015-5041

CVE-2015-5041

Description

The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote attackers to obtain sensitive information or inject data by invoking non-public interface methods.

Affected products

11
  • cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*
    Range: >=6.0.0.0,<6.0.16.20
  • cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*
    Range: <=3.0.9.20
  • Red Hat/Satellite2 versions
    cpe:2.3:a:redhat:satellite:5.6:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:redhat:satellite:5.6:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:satellite:5.7:*:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:ltss:*:*:*+ 3 more
    • cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:ltss:*:*:*
    • cpe:2.3:o:suse:linux_enterprise_server:11:sp4:*:*:*:*:*:*
    • cpe:2.3:o:suse:linux_enterprise_server:12:sp1:*:*:*:*:*:*
    • cpe:2.3:o:suse:suse_linux_enterprise_server:12:*:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp4:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp4:*:*:*:*:*:*
    • cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:*:*:*:*:*:*:*
    • cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:sp1:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.