Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE: 2015:1345-1 Critical Update: IBM Java Security Enhancements

suse
Calendar Grey August 5, 2015
Dist Suse Esm H88
SUSE releases an essential patch for java-1_6_0-ibm addressing 17 security flaws. Important enhancements made for improved protection.
An update that fixes 17 vulnerabilities is now available

Summary

IBM Java was updated to 6.0-16.7 to fix several security issues. The following vulnerabilities were fixed: * CVE-2015-1931: IBM Java Security Components store plain text data in memory dumps, which could allow a local attacker to obtain information to aid in further attacks against the system. * CVE-2015-2590: Easily exploitable vulnerability in the Libraries component allowed successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability could have resulted in unauthorized Operating System takeover including arbitrary code execution. * CVE-2015-2601: Easily exploitable vulnerability in the JCE component allowed successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability could have resulted

References

#935540 #936844 #938895

Cross- CVE-2015-1931 CVE-2015-2590 CVE-2015-2601

CVE-2015-2621 CVE-2015-2625 CVE-2015-2632

CVE-2015-2637 CVE-2015-2638 CVE-2015-2664

CVE-2015-2808 CVE-2015-4000 CVE-2015-4731

CVE-2015-4732 CVE-2015-4733 CVE-2015-4748

CVE-2015-4749 CVE-2015-4760

Affected Products:

SUSE Linux Enterprise Module for Legacy Software 12

https://www.suse.com/security/cve/CVE-2015-1931.html

https://www.suse.com/security/cve/CVE-2015-2590.html

https://www.suse.com/security/cve/CVE-2015-2601.html

https://www.suse.com/security/cve/CVE-2015-2621.html

https://www.suse.com/security/cve/CVE-2015-2625.html

https://www.suse.com/security/cve/CVE-2015-2632.html

https://www.suse.com/security/cve/CVE-2015-2637.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:1345-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here