Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

SUSE: 2025:01788-1 important: Java security issues and fixes

suse
Calendar Grey June 2, 2025
Dist Suse Esm H88
Important patch for SUSE addressing several vulnerabilities in Java, including potential DoS attacks and risks of unauthorized entry.
* bsc#1241274 * bsc#1241275 * bsc#1241276 * bsc#1242208 * bsc#1243429

Summary

## This update for java-1_8_0-ibm fixes the following issues: Update to Java 8.0 Service Refresh 8 Fix Pack 45. Security issues fixed: * Oracle April 15 2025 CPU (bsc#1242208) * CVE-2025-21587: unauthorized access, deletion and modification of critical data via the JSSE component (bsc#1241274). * CVE-2025-30691: unauthorized access to data via the Compiler component (bsc#1241275). * CVE-2025-30698: unauthorized access to data and ability to cause a partial DoS via the 2D component (bsc#1241276). * IBM Security Update May 2025 * CVE-2025-4447: stack based buffer overflow in Eclipse OpenJ9 through modification of file that is read when the JVM starts (bsc#1243429). Other changes and issues fixed: * Security: * Avoid memory leak during aes cipher initialization operations for IBMJCEPlus

References

* bsc#1241274

* bsc#1241275

* bsc#1241276

* bsc#1242208

* bsc#1243429

Cross-

* CVE-2025-21587

* CVE-2025-30691

* CVE-2025-30698

* CVE-2025-4447

CVSS scores:

* CVE-2025-21587 ( SUSE ): 9.1

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

* CVE-2025-21587 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

* CVE-2025-21587 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

* CVE-2025-30691 ( SUSE ): 6.3

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

* CVE-2025-30691 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

* CVE-2025-30691 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

* CVE-2025-30698 ( SUSE ): 6.3

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2025:01788-1
Release Date: 2025-05-31T10:34:59Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here