VYPR

rpm package

suse/java-1_8_0-ibm&distro=SUSE OpenStack Cloud Crowbar 8

pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208

Vulnerabilities (90)

  • CVE-2020-2583LowJan 15, 2020
    affected < 1.8.0_sr6.5-30.63.1fixed 1.8.0_sr6.5-30.63.1

    Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with

  • CVE-2019-17631CriOct 17, 2019
    affected < 1.8.0_sr6.0-30.60.1fixed 1.8.0_sr6.0-30.60.1

    From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privilege checks.

  • CVE-2019-2999MedOct 16, 2019
    affected < 1.8.0_sr6.0-30.60.1fixed 1.8.0_sr6.0-30.60.1

    Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise

  • CVE-2019-2996MedOct 16, 2019
    affected < 1.8.0_sr6.0-30.60.1fixed 1.8.0_sr6.0-30.60.1

    Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Deployment). The supported version that is affected is Java SE: 8u221; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple

  • CVE-2019-2992LowOct 16, 2019
    affected < 1.8.0_sr6.0-30.60.1fixed 1.8.0_sr6.0-30.60.1

    Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access

  • CVE-2019-2989MedOct 16, 2019
    affected < 1.8.0_sr6.0-30.60.1fixed 1.8.0_sr6.0-30.60.1

    Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with networ

  • CVE-2019-2988LowOct 16, 2019
    affected < 1.8.0_sr6.0-30.60.1fixed 1.8.0_sr6.0-30.60.1

    Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access

  • CVE-2019-2983LowOct 16, 2019
    affected < 1.8.0_sr6.0-30.60.1fixed 1.8.0_sr6.0-30.60.1

    Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with net

  • CVE-2019-2981LowOct 16, 2019
    affected < 1.8.0_sr6.0-30.60.1fixed 1.8.0_sr6.0-30.60.1

    Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network acce

  • CVE-2019-2978LowOct 16, 2019
    affected < 1.8.0_sr6.0-30.60.1fixed 1.8.0_sr6.0-30.60.1

    Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with networ

  • CVE-2019-2975MedOct 16, 2019
    affected < 1.8.0_sr6.0-30.60.1fixed 1.8.0_sr6.0-30.60.1

    Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Supported versions that are affected are Java SE: 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access

  • CVE-2019-2973LowOct 16, 2019
    affected < 1.8.0_sr6.0-30.60.1fixed 1.8.0_sr6.0-30.60.1

    Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network acce

  • CVE-2019-2964LowOct 16, 2019
    affected < 1.8.0_sr6.0-30.60.1fixed 1.8.0_sr6.0-30.60.1

    Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with netwo

  • CVE-2019-2962LowOct 16, 2019
    affected < 1.8.0_sr6.0-30.60.1fixed 1.8.0_sr6.0-30.60.1

    Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access

  • CVE-2019-2958MedOct 16, 2019
    affected < 1.8.0_sr6.0-30.60.1fixed 1.8.0_sr6.0-30.60.1

    Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network

  • CVE-2019-2949MedOct 16, 2019
    affected < 1.8.0_sr6.10-30.69.1fixed 1.8.0_sr6.10-30.69.1

    Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Kerberos). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network

  • CVE-2019-2945LowOct 16, 2019
    affected < 1.8.0_sr6.0-30.60.1fixed 1.8.0_sr6.0-30.60.1

    Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with networ

  • CVE-2019-2933LowOct 16, 2019
    affected < 1.8.0_sr6.0-30.60.1fixed 1.8.0_sr6.0-30.60.1

    Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network

  • CVE-2019-4473HigAug 5, 2019
    affected < 1.8.0_sr5.40-30.54.1fixed 1.8.0_sr5.40-30.54.1

    Multiple binaries in IBM SDK, Java Technology Edition 7, 7R, and 8 on the AIX platform use insecure absolute RPATHs, which may facilitate code injection and privilege elevation by local users. IBM X-Force ID: 163984.

  • CVE-2019-11775HigJul 30, 2019
    affected < 1.8.0_sr5.40-30.54.1fixed 1.8.0_sr5.40-30.54.1

    All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is a condition that is moved out of the loop that reads a field we may not privatize the value of th

Page 4 of 5