Sensitive data lingers in memory allowing access by an administrator of the WebSphere eXtreme Scale server. This is addressed in the interim fix.
CVEID: CVE-2015-7418**
DESCRIPTION:** IBM WebSphere eXtreme Scale allows some sensitive data to linger in memory instead of being overwritten which could allow a local user with administrator privileges to obtain sensitive information.
CVSS Base Score: 4.4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/107576 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N)
WebSphere eXtreme Scale 7.1.0
WebSphere eXtreme Scale 7.1.1
WebSphere eXtreme Scale 8.5
WebSphere eXtreme Scale 8.6
<Product
| VRMF| APAR| Remediation/First Fix
—|—|—|—
WebSphere eXtreme Scale| 7.1| PI51734| Refer to the Version 7.1 table in the Recommended Fixes page for WebSphere eXtreme Scale.
WebSphere eXtreme Scale| 7.1.1
8.5
8.6
| PI51742| Refer to the Version 7.1.1,8.5, or8.6 table in the Recommended Fixes page for WebSphere eXtreme Scale.
There is no workaround. The interim fix must be applied to correct the problem.
CPE | Name | Operator | Version |
---|---|---|---|
websphere extreme scale | eq | 8.6 | |
websphere extreme scale | eq | 8.5.0.1 | |
websphere extreme scale | eq | 7.1.1 | |
websphere extreme scale | eq | 7.1 |