CVE-2015-1914: IBM Java

Medium severity, CVSS 5.0. EPSS: 4% chance of exploitation in the next 30 days.

IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to bypass "permission checks" and obtain sensitive information via vectors related to the Java Virtual Machine.

Affected products

  • IBM Java: from 5.0.0.0, before 5.0.16.10 (fixed in 5.0.16.10); from 6.0.0.0, before 6.0.16.4 (fixed in 6.0.16.4); from 6.1.0.0, before 6.1.8.4 (fixed in 6.1.8.4); from 7.0.0.0, before 7.0.9.0 (fixed in 7.0.9.0); from 7.1.0.0, before 7.1.3.0 (fixed in 7.1.3.0)

Published 2015-07-02. Last modified 2026-06-17.