SUSE-SU-2023:2476-1
Dashboard / Vulnerabilities / SUSE-SU-2023:2476-1
SUSE-SU-2023:2476-1
Summary: Security update for java-1_8_0-ibm
Details: This update for java-1_8_0-ibm fixes the following issues: - CVE-2023-21930: Fixed possible compromise from unauthenticated attacker with network access via TLS (bsc#1210628). - CVE-2023-21937: Fixed vulnerability inside the networking component (bsc#1210631). - CVE-2023-21938: Fixed vulnerability inside the library component (bsc#1210632). - CVE-2023-21939: Fixed vulnerability inside the swing component (bsc#1210634). - CVE-2023-21968: Fixed vulnerability inside the library component (bsc#1210637). - CVE-2023-2597: Fixed buffer overflow in shared cache implementation (bsc#1211615). - CVE-2023-21967: Fixed vulnerability inside the JSSE component (bsc#1210636). - CVE-2023-21954: Fixed vulnerability inside the hotspot component (bsc#1210635). Additional reference fixed already in 8.0.7.15: - CVE-2023-30441: Fixed components that could have exposed sensitive information using a combination of flaws and configurations (bsc#1210711).
References: https://www.suse.com/support/update/announcement/2023/suse-su-20232476-1/, https://bugzilla.suse.com/1210628, https://bugzilla.suse.com/1210631, https://bugzilla.suse.com/1210632, https://bugzilla.suse.com/1210634, https://bugzilla.suse.com/1210635, https://bugzilla.suse.com/1210636, https://bugzilla.suse.com/1210637, https://bugzilla.suse.com/1210711, https://bugzilla.suse.com/1210826, https://bugzilla.suse.com/1211615, https://www.suse.com/security/cve/CVE-2023-21930, https://www.suse.com/security/cve/CVE-2023-21937, https://www.suse.com/security/cve/CVE-2023-21938, https://www.suse.com/security/cve/CVE-2023-21939, https://www.suse.com/security/cve/CVE-2023-21954, https://www.suse.com/security/cve/CVE-2023-21967, https://www.suse.com/security/cve/CVE-2023-21968, https://www.suse.com/security/cve/CVE-2023-2597, https://www.suse.com/security/cve/CVE-2023-30441
Affected packages
Package
Name: java-1_8_0-ibm
Purl: pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20OpenStack%20Cloud%209
Affected ranges
Type: ECOSYSTEM
Events:
