rpm package
suse/java-1_8_0-ibm&distro=SUSE Linux Enterprise Module for Legacy 15 SP1
pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2015%20SP1
Vulnerabilities (65)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-2975 | Med | 4.8 | < 1.8.0_sr6.0-3.30.1 | 1.8.0_sr6.0-3.30.1 | Oct 16, 2019 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Supported versions that are affected are Java SE: 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access | |
| CVE-2019-2973 | Low | 3.7 | < 1.8.0_sr6.0-3.30.1 | 1.8.0_sr6.0-3.30.1 | Oct 16, 2019 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network acce | |
| CVE-2019-2964 | Low | 3.7 | < 1.8.0_sr6.0-3.30.1 | 1.8.0_sr6.0-3.30.1 | Oct 16, 2019 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with netwo | |
| CVE-2019-2962 | Low | 3.7 | < 1.8.0_sr6.0-3.30.1 | 1.8.0_sr6.0-3.30.1 | Oct 16, 2019 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access | |
| CVE-2019-2958 | Med | 5.9 | < 1.8.0_sr6.0-3.30.1 | 1.8.0_sr6.0-3.30.1 | Oct 16, 2019 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network | |
| CVE-2019-2949 | Med | 6.8 | < 1.8.0_sr6.10-3.38.1 | 1.8.0_sr6.10-3.38.1 | Oct 16, 2019 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Kerberos). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network | |
| CVE-2019-2945 | Low | 3.1 | < 1.8.0_sr6.0-3.30.1 | 1.8.0_sr6.0-3.30.1 | Oct 16, 2019 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with networ | |
| CVE-2019-2933 | Low | 3.1 | < 1.8.0_sr6.0-3.30.1 | 1.8.0_sr6.0-3.30.1 | Oct 16, 2019 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network | |
| CVE-2019-4473 | Hig | 7.8 | < 1.8.0_sr5.40-3.24.1 | 1.8.0_sr5.40-3.24.1 | Aug 5, 2019 | Multiple binaries in IBM SDK, Java Technology Edition 7, 7R, and 8 on the AIX platform use insecure absolute RPATHs, which may facilitate code injection and privilege elevation by local users. IBM X-Force ID: 163984. | |
| CVE-2019-11775 | Hig | 7.4 | < 1.8.0_sr5.40-3.24.1 | 1.8.0_sr5.40-3.24.1 | Jul 30, 2019 | All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is a condition that is moved out of the loop that reads a field we may not privatize the value of th | |
| CVE-2019-2816 | Med | 4.8 | < 1.8.0_sr5.40-3.24.1 | 1.8.0_sr5.40-3.24.1 | Jul 23, 2019 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker wi | |
| CVE-2019-2786 | Low | 3.4 | < 1.8.0_sr5.40-3.24.1 | 1.8.0_sr5.40-3.24.1 | Jul 23, 2019 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker with networ | |
| CVE-2019-2769 | Med | 5.3 | < 1.8.0_sr5.40-3.24.1 | 1.8.0_sr5.40-3.24.1 | Jul 23, 2019 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with | |
| CVE-2019-2766 | Low | 3.1 | < 1.8.0_sr5.40-3.24.1 | 1.8.0_sr5.40-3.24.1 | Jul 23, 2019 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker wi | |
| CVE-2019-2762 | Med | 5.3 | < 1.8.0_sr5.40-3.24.1 | 1.8.0_sr5.40-3.24.1 | Jul 23, 2019 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with | |
| CVE-2019-11772 | Cri | 9.8 | < 1.8.0_sr5.40-3.24.1 | 1.8.0_sr5.40-3.24.1 | Jul 17, 2019 | In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bounds when compiled by the JIT. This allows arbitrary writes to any 32-bit address or beyond the end of a | |
| CVE-2019-11771 | Hig | 7.8 | < 1.8.0_sr5.40-3.24.1 | 1.8.0_sr5.40-3.24.1 | Jul 17, 2019 | AIX builds of Eclipse OpenJ9 before 0.15.0 contain unused RPATHs which may facilitate code injection and privilege elevation by local users. | |
| CVE-2019-2698 | Hig | 8.1 | < 1.8.0_sr5.35-3.20.1 | 1.8.0_sr5.35-3.20.1 | Apr 23, 2019 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Suc | |
| CVE-2019-2697 | Hig | 8.1 | < 1.8.0_sr5.35-3.20.1 | 1.8.0_sr5.35-3.20.1 | Apr 23, 2019 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Suc | |
| CVE-2019-2684 | Med | 5.9 | < 1.8.0_sr5.35-3.20.1 | 1.8.0_sr5.35-3.20.1 | Apr 23, 2019 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit vulnerability allows unauthenticated attacker with network |
- affected < 1.8.0_sr6.0-3.30.1fixed 1.8.0_sr6.0-3.30.1
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Supported versions that are affected are Java SE: 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access
- affected < 1.8.0_sr6.0-3.30.1fixed 1.8.0_sr6.0-3.30.1
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network acce
- affected < 1.8.0_sr6.0-3.30.1fixed 1.8.0_sr6.0-3.30.1
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with netwo
- affected < 1.8.0_sr6.0-3.30.1fixed 1.8.0_sr6.0-3.30.1
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access
- affected < 1.8.0_sr6.0-3.30.1fixed 1.8.0_sr6.0-3.30.1
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network
- affected < 1.8.0_sr6.10-3.38.1fixed 1.8.0_sr6.10-3.38.1
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Kerberos). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network
- affected < 1.8.0_sr6.0-3.30.1fixed 1.8.0_sr6.0-3.30.1
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with networ
- affected < 1.8.0_sr6.0-3.30.1fixed 1.8.0_sr6.0-3.30.1
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network
- affected < 1.8.0_sr5.40-3.24.1fixed 1.8.0_sr5.40-3.24.1
Multiple binaries in IBM SDK, Java Technology Edition 7, 7R, and 8 on the AIX platform use insecure absolute RPATHs, which may facilitate code injection and privilege elevation by local users. IBM X-Force ID: 163984.
- affected < 1.8.0_sr5.40-3.24.1fixed 1.8.0_sr5.40-3.24.1
All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is a condition that is moved out of the loop that reads a field we may not privatize the value of th
- affected < 1.8.0_sr5.40-3.24.1fixed 1.8.0_sr5.40-3.24.1
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker wi
- affected < 1.8.0_sr5.40-3.24.1fixed 1.8.0_sr5.40-3.24.1
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker with networ
- affected < 1.8.0_sr5.40-3.24.1fixed 1.8.0_sr5.40-3.24.1
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with
- affected < 1.8.0_sr5.40-3.24.1fixed 1.8.0_sr5.40-3.24.1
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker wi
- affected < 1.8.0_sr5.40-3.24.1fixed 1.8.0_sr5.40-3.24.1
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with
- affected < 1.8.0_sr5.40-3.24.1fixed 1.8.0_sr5.40-3.24.1
In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bounds when compiled by the JIT. This allows arbitrary writes to any 32-bit address or beyond the end of a
- affected < 1.8.0_sr5.40-3.24.1fixed 1.8.0_sr5.40-3.24.1
AIX builds of Eclipse OpenJ9 before 0.15.0 contain unused RPATHs which may facilitate code injection and privilege elevation by local users.
- affected < 1.8.0_sr5.35-3.20.1fixed 1.8.0_sr5.35-3.20.1
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Suc
- affected < 1.8.0_sr5.35-3.20.1fixed 1.8.0_sr5.35-3.20.1
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Suc
- affected < 1.8.0_sr5.35-3.20.1fixed 1.8.0_sr5.35-3.20.1
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit vulnerability allows unauthenticated attacker with network
Page 3 of 4