The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote attackers to obtain sensitive information or inject data by invoking non-public interface methods.
2016-06-06T17:59:00.220
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 9.1 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:N
10.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | java_sdk | < 6.0.16.20 | Yes |
Application | ibm | java_sdk | < 6.1.8.20 | Yes |
Application | ibm | java_sdk | < 7.0.9.30 | Yes |
Application | ibm | java_sdk | < 7.1.3.30 | Yes |
Operating System | suse | linux_enterprise_server | 11 | Yes |
Operating System | suse | linux_enterprise_server | 11 | Yes |
Operating System | suse | linux_enterprise_server | 12 | Yes |
Operating System | suse | linux_enterprise_software_development_kit | 11 | Yes |
Operating System | suse | linux_enterprise_software_development_kit | 12 | Yes |
Operating System | suse | linux_enterprise_software_development_kit | 12 | Yes |
Operating System | suse | suse_linux_enterprise_server | 12 | Yes |
Application | ibm | websphere_application_server | ≤ 3.0.9.20 | Yes |
Application | redhat | satellite | 5.6 | Yes |
Application | redhat | satellite | 5.7 | Yes |