Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-2601

Опубликовано: 14 июл. 2015
Источник: redhat
CVSS2: 5

Описание

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, JRockit R28.3.6, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality via vectors related to JCE.

It was discovered that the JCE component in OpenJDK failed to use constant time comparisons in multiple cases. An attacker could possibly use these flaws to disclose sensitive information by measuring the time used to perform operations using these non-constant time comparisons.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-385
https://bugzilla.redhat.com/show_bug.cgi?id=1242019OpenJDK: non-constant time comparisons in crypto code (JCE, 8074865)

5 Medium

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, JRockit R28.3.6, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality via vectors related to JCE.

nvd
около 10 лет назад

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, JRockit R28.3.6, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality via vectors related to JCE.

debian
около 10 лет назад

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, JRoc ...

github
около 3 лет назад

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, JRockit R28.3.6, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality via vectors related to JCE.

fstec
около 10 лет назад

Уязвимость программных платформ Java Platform и Jrockit, позволяющая нарушителю нарушить конфиденциальность информации

5 Medium

CVSS2