[SUSE-SU-2015:1331-1] Security update for java-1_7_1-ibm

Severity Important
Affected Packages 8
CVEs 20

Security update for java-1_7_1-ibm

IBM Java was updated to 7.1-3.10 to fix several security issues.

The following vulnerabilities were fixed:

  • CVE-2015-1931: IBM Java Security Components store plain text data in memory dumps, which could allow a local attacker to obtain information to aid in further attacks against the system.
  • CVE-2015-2590: Easily exploitable vulnerability in the Libraries component allowed successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability could have resulted in unauthorized Operating System takeover including arbitrary code execution.
  • CVE-2015-2601: Easily exploitable vulnerability in the JCE component allowed successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability could have resulted in unauthorized read access to a subset of Java accessible data.
  • CVE-2015-2613: Easily exploitable vulnerability in the JCE component allowed successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability could have resulted in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data.
  • CVE-2015-2619: Easily exploitable vulnerability in the 2D component allowed successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability could have resulted in unauthorized read access to a subset of Java accessible data.
  • CVE-2015-2621: Easily exploitable vulnerability in the JMX component allowed successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability could have resulted in unauthorized read access to a subset of Java accessible data.
  • CVE-2015-2625: Very difficult to exploit vulnerability in the JSSE component allowed successful unauthenticated network attacks via SSL/TLS. Successful attack of this vulnerability could have resulted in unauthorized read access to a subset of Java accessible data.
  • CVE-2015-2632: Easily exploitable vulnerability in the 2D component allowed successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability could have resulted in unauthorized read access to a subset of Java accessible data.
  • CVE-2015-2637: Easily exploitable vulnerability in the 2D component allowed successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability could have resulted in unauthorized read access to a subset of Java accessible data.
  • CVE-2015-2638: Easily exploitable vulnerability in the 2D component allowed successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability could have resulted in unauthorized Operating System takeover including arbitrary code execution.
  • CVE-2015-2664: Difficult to exploit vulnerability in the Deployment component requiring logon to Operating System. Successful attack of this vulnerability could have resulted in unauthorized Operating System takeover including arbitrary code execution.
  • CVE-2015-2808: Very difficult to exploit vulnerability in the JSSE component allowed successful unauthenticated network attacks via SSL/TLS. Successful attack of this vulnerability could have resulted in unauthorized update, insert or delete access to some Java accessible data as well as read access to a subset of Java accessible data.
  • CVE-2015-4000: Very difficult to exploit vulnerability in the JSSE component allowed successful unauthenticated network attacks via SSL/TLS. Successful attack of this vulnerability could have resulted in unauthorized update, insert or delete access to some Java accessible data as well as read access to a subset of Java Embedded accessible data.
  • CVE-2015-4729: Very difficult to exploit vulnerability in the Deployment component allowed successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability could have resulted in unauthorized update, insert or delete access to some Java SE accessible data as well as read access to a subset of Java SE accessible data.
  • CVE-2015-4731: Easily exploitable vulnerability in the JMX component allowed successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability could have resulted in unauthorized Operating System takeover including arbitrary code execution.
  • CVE-2015-4732: Easily exploitable vulnerability in the Libraries component allowed successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability could have resulted in unauthorized Operating System takeover including arbitrary code execution.
  • CVE-2015-4733: Easily exploitable vulnerability in the RMI component allowed successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability could have resulted in unauthorized Operating System takeover including arbitrary code execution.
  • CVE-2015-4748: Very difficult to exploit vulnerability in the Security component allowed successful unauthenticated network attacks via OCSP. Successful attack of this vulnerability could have resulted in unauthorized Operating System takeover including arbitrary code execution.
  • CVE-2015-4749: Difficult to exploit vulnerability in the JNDI component allowed successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability could have resulted in unauthorized ability to cause a partial denial of service (partial DOS).
  • CVE-2015-4760: Easily exploitable vulnerability in the 2D component allowed successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability could have resulted in unauthorized Operating System takeover including arbitrary code execution.
ID
SUSE-SU-2015:1331-1
Severity
important
URL
https://www.suse.com/support/update/announcement/2015/suse-su-20151331-1/
Published
2015-07-28T11:22:42
(9 years ago)
Modified
2015-07-28T11:22:42
(9 years ago)
Rights
Copyright 2024 SUSE LLC. All rights reserved.
Other Advisories
Source # ID Name URL
Suse SUSE ratings https://www.suse.com/support/security/rating/
Suse URL of this CSAF notice https://ftp.suse.com/pub/projects/security/csaf/suse-su-2015_1331-1.json
Suse URL for SUSE-SU-2015:1331-1 https://www.suse.com/support/update/announcement/2015/suse-su-20151331-1/
Suse E-Mail link for SUSE-SU-2015:1331-1 https://lists.suse.com/pipermail/sle-security-updates/2015-July/001520.html
Bugzilla SUSE Bug 935540 https://bugzilla.suse.com/935540
Bugzilla SUSE Bug 938895 https://bugzilla.suse.com/938895
CVE SUSE CVE CVE-2015-1931 page https://www.suse.com/security/cve/CVE-2015-1931/
CVE SUSE CVE CVE-2015-2590 page https://www.suse.com/security/cve/CVE-2015-2590/
CVE SUSE CVE CVE-2015-2601 page https://www.suse.com/security/cve/CVE-2015-2601/
CVE SUSE CVE CVE-2015-2613 page https://www.suse.com/security/cve/CVE-2015-2613/
CVE SUSE CVE CVE-2015-2619 page https://www.suse.com/security/cve/CVE-2015-2619/
CVE SUSE CVE CVE-2015-2621 page https://www.suse.com/security/cve/CVE-2015-2621/
CVE SUSE CVE CVE-2015-2625 page https://www.suse.com/security/cve/CVE-2015-2625/
CVE SUSE CVE CVE-2015-2632 page https://www.suse.com/security/cve/CVE-2015-2632/
CVE SUSE CVE CVE-2015-2637 page https://www.suse.com/security/cve/CVE-2015-2637/
CVE SUSE CVE CVE-2015-2638 page https://www.suse.com/security/cve/CVE-2015-2638/
CVE SUSE CVE CVE-2015-2664 page https://www.suse.com/security/cve/CVE-2015-2664/
CVE SUSE CVE CVE-2015-2808 page https://www.suse.com/security/cve/CVE-2015-2808/
CVE SUSE CVE CVE-2015-4000 page https://www.suse.com/security/cve/CVE-2015-4000/
CVE SUSE CVE CVE-2015-4729 page https://www.suse.com/security/cve/CVE-2015-4729/
CVE SUSE CVE CVE-2015-4731 page https://www.suse.com/security/cve/CVE-2015-4731/
CVE SUSE CVE CVE-2015-4732 page https://www.suse.com/security/cve/CVE-2015-4732/
CVE SUSE CVE CVE-2015-4733 page https://www.suse.com/security/cve/CVE-2015-4733/
CVE SUSE CVE CVE-2015-4748 page https://www.suse.com/security/cve/CVE-2015-4748/
CVE SUSE CVE CVE-2015-4749 page https://www.suse.com/security/cve/CVE-2015-4749/
CVE SUSE CVE CVE-2015-4760 page https://www.suse.com/security/cve/CVE-2015-4760/
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/suse/java-1_7_1-ibm?arch=x86_64&distro=sles-12 suse java-1_7_1-ibm < 1.7.1_sr3.10-14.1 sles-12 x86_64
Affected pkg:rpm/suse/java-1_7_1-ibm?arch=s390x&distro=sles-12 suse java-1_7_1-ibm < 1.7.1_sr3.10-14.1 sles-12 s390x
Affected pkg:rpm/suse/java-1_7_1-ibm?arch=ppc64le&distro=sles-12 suse java-1_7_1-ibm < 1.7.1_sr3.10-14.1 sles-12 ppc64le
Affected pkg:rpm/suse/java-1_7_1-ibm-plugin?arch=x86_64&distro=sles-12 suse java-1_7_1-ibm-plugin < 1.7.1_sr3.10-14.1 sles-12 x86_64
Affected pkg:rpm/suse/java-1_7_1-ibm-jdbc?arch=x86_64&distro=sles-12 suse java-1_7_1-ibm-jdbc < 1.7.1_sr3.10-14.1 sles-12 x86_64
Affected pkg:rpm/suse/java-1_7_1-ibm-jdbc?arch=s390x&distro=sles-12 suse java-1_7_1-ibm-jdbc < 1.7.1_sr3.10-14.1 sles-12 s390x
Affected pkg:rpm/suse/java-1_7_1-ibm-jdbc?arch=ppc64le&distro=sles-12 suse java-1_7_1-ibm-jdbc < 1.7.1_sr3.10-14.1 sles-12 ppc64le
Affected pkg:rpm/suse/java-1_7_1-ibm-alsa?arch=x86_64&distro=sles-12 suse java-1_7_1-ibm-alsa < 1.7.1_sr3.10-14.1 sles-12 x86_64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...