Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

SUSE: Security Advisory (SUSE-SU-2022:0166-1)

Information

Severity

Severity

High

Family

Family

SuSE Local Security Checks

CVSSv2 Base

CVSSv2 Base

7.5

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

Solution Type

Solution Type

Vendor Patch

Created

Created

2 years ago

Modified

Modified

2 years ago

Summary

The remote host is missing an update for the 'java-1_7_1-ibm' package(s) announced via the SUSE-SU-2022:0166-1 advisory.

Insight

Insight

This update for java-1_7_1-ibm fixes the following issues: Update to Java 7.1 Service Refresh 5 Fix Pack 0 CVE-2021-41035: before version 0.29.0, the openj9 JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods. (bsc#1194198, bsc#1192052) CVE-2021-35586: Excessive memory allocation in BMPImageReader. (bsc#1191914) CVE-2021-35564: Certificates with end dates too far in the future can corrupt keystore. (bsc#1191913) CVE-2021-35559: Excessive memory allocation in RTFReader. (bsc#1191911) CVE-2021-35556: Excessive memory allocation in RTFParser. (bsc#1191910) CVE-2021-35565: Loop in HttpsServer triggered during TLS session close. (bsc#1191909) CVE-2021-35588: Incomplete validation of inner class references in ClassFileParser. (bsc#1191905) CVE-2021-2341: Fixed a flaw inside the FtpClient. (bsc#1188564) CVE-2021-2369: JAR file handling problem containing multiple MANIFEST.MF files. (bsc#1188565) CVE-2021-2432: Fixed a vulnerability in the omponent JNDI. (bsc#1188568) CVE-2021-2163: Incomplete enforcement of JAR signing disabled algorithms. (bsc#1185055)

Affected Software

Affected Software

'java-1_7_1-ibm' package(s) on SUSE Linux Enterprise Server 12-SP2, SUSE Linux Enterprise Server 12-SP3, SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 12-SP5, SUSE Linux Enterprise Server for SAP 12-SP3, SUSE Linux Enterprise Server for SAP 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5, SUSE OpenStack Cloud 8, SUSE OpenStack Cloud 9, SUSE OpenStack Cloud Crowbar 8, SUSE OpenStack Cloud Crowbar 9.

Detection Method

Detection Method

Checks if a vulnerable package version is present on the target host.

Solution

Solution

Please install the updated package(s).