Alpine: openjdk7: security update to 7.85.-r0 (deprecated)

critical Tenable Self-Hosted Container Security Plugin ID 401088

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows
remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI, a
different vulnerability than CVE-2015-4860. (CVE-2015-4883)

- Unspecified vulnerability in Oracle Java SE 6u101, 7u85 and 8u60, and Java SE Embedded 8u51, allows remote
attackers to affect confidentiality via vectors related to JGSS. (CVE-2015-4734)

- Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60; Java SE Embedded 8u51; and JRockit
R28.3.7 allows remote attackers to affect availability via vectors related to JAXP, a different
vulnerability than CVE-2015-4893 and CVE-2015-4911. (CVE-2015-4803)

- Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows
remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to
Serialization. (CVE-2015-4805)

- Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows
remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.
(CVE-2015-4806)

See Also

https://git.alpinelinux.org/aports/commit/?id=791de7d130c9c4e35c7d9b209c08182f54853914

https://git.alpinelinux.org/aports/commit/?id=f227313aae602dec3a6c8c11123807028c9062d6

Plugin Details

Severity: Critical

ID: 401088

Version: Revision 1.27

Type: Local

Published: 8/16/2023

Updated: 6/22/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.0

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2015-4883

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2015-4806

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/25/2015

Vulnerability Publication Date: 10/20/2015

Reference Information

CVE: CVE-2015-4734, CVE-2015-4803, CVE-2015-4805, CVE-2015-4806, CVE-2015-4835, CVE-2015-4840, CVE-2015-4842, CVE-2015-4843, CVE-2015-4844, CVE-2015-4860, CVE-2015-4872, CVE-2015-4881, CVE-2015-4882, CVE-2015-4883, CVE-2015-4893, CVE-2015-4903, CVE-2015-4911

BID: 77126, 77148, 77154, 77159, 77160, 77161, 77162, 77163, 77164, 77181, 77192, 77194, 77200, 77207, 77209, 77211, 77242