SuSE 11.3 Security Update : IBM Java (SAT Patch Number 9999)

This script is Copyright (C) 2014-2015 Tenable Network Security, Inc.


Synopsis :

The remote SuSE 11 host is missing one or more security updates.

Description :

java-1_7_0-ibm has been updated to version 1.7.0_sr7.2 to fix 21
security issues.

These security issues have been fixed :

- Unspecified vulnerability. (CVE-2014-3065)

- The SSL protocol 3.0, as used in OpenSSL through 1.0.1i
and other products, uses nondeterministic CBC padding,
which makes it easier for man-in-the-middle attackers to
obtain cleartext data via a padding-oracle attack, aka
the 'POODLE' issue. (CVE-2014-3566)

- Unspecified vulnerability in Oracle Java SE 6u81, 7u67,
and 8u20, and Java SE Embedded 7u60, allows remote
attackers to affect confidentiality, integrity, and
availability via vectors related to AWT. (CVE-2014-6513)

- Unspecified vulnerability in Oracle Java SE 7u67 and
8u20 allows remote attackers to affect confidentiality,
integrity, and availability via unknown vectors.
(CVE-2014-6456)

- Unspecified vulnerability in Oracle Java SE 6u81, 7u67,
and 8u20 allows remote attackers to affect
confidentiality, integrity, and availability via unknown
vectors related to Deployment, a different vulnerability
than CVE-2014-4288 / CVE-2014-6493 / CVE-2014-6532.
(CVE-2014-6503)

- Unspecified vulnerability in Oracle Java SE 6u81, 7u67,
and 8u20 allows remote attackers to affect
confidentiality, integrity, and availability via unknown
vectors related to Deployment, a different vulnerability
than CVE-2014-4288 / CVE-2014-6493 / CVE-2014-6503.
(CVE-2014-6532)

- Unspecified vulnerability in Oracle Java SE 6u81, 7u67,
and 8u20 allows remote attackers to affect
confidentiality, integrity, and availability via unknown
vectors related to Deployment, a different vulnerability
than CVE-2014-6493 / CVE-2014-6503 / CVE-2014-6532.
(CVE-2014-4288)

- Unspecified vulnerability in Oracle Java SE 6u81, 7u67,
and 8u20 allows remote attackers to affect
confidentiality, integrity, and availability via unknown
vectors related to Deployment, a different vulnerability
than CVE-2014-4288 / CVE-2014-6503 / CVE-2014-6532.
(CVE-2014-6493)

- Unspecified vulnerability in Oracle Java SE 6u81, 7u67,
and 8u20, when running on Firefox, allows remote
attackers to affect confidentiality, integrity, and
availability via unknown vectors related to Deployment.
(CVE-2014-6492)

- Unspecified vulnerability in Oracle Java SE 6u81, 7u67,
and 8u20 allows local users to affect confidentiality,
integrity, and availability via unknown vectors related
to Deployment. (CVE-2014-6458)

- Unspecified vulnerability in Oracle Java SE 6u81, 7u67,
and 8u20, when running on Internet Explorer, allows
local users to affect confidentiality, integrity, and
availability via unknown vectors related to Deployment.
(CVE-2014-6466)

- Unspecified vulnerability in Oracle Java SE 5.0u71,
6u81, 7u67, and 8u20, and Java SE Embedded 7u60, allows
remote attackers to affect confidentiality, integrity,
and availability via unknown vectors related to
Libraries. (CVE-2014-6506)

- Unspecified vulnerability in Oracle Java SE 7u67 and
8u20 allows remote attackers to affect integrity via
unknown vectors related to Deployment, a different
vulnerability than CVE-2014-6527. (CVE-2014-6476)

- Unspecified vulnerability in Oracle Java SE 6u81, 7u67,
and 8u20 allows remote attackers to affect integrity via
unknown vectors related to Deployment. (CVE-2014-6515)

- Unspecified vulnerability in Oracle Java SE 5.0u71,
6u81, 7u67, and 8u20 allows remote attackers to affect
confidentiality via unknown vectors related to 2D.
(CVE-2014-6511)

- Unspecified vulnerability in Oracle Java SE 5.0u71,
6u81, 7u67, and 8u20, and Java SE Embedded 7u60, allows
remote attackers to affect confidentiality via unknown
vectors related to Libraries. (CVE-2014-6531)

- Unspecified vulnerability in Oracle Java SE 5.0u71,
6u81, 7u67, and 8u20; Java SE Embedded 7u60; and JRockit
R27.8.3 and R28.3.3 allows remote attackers to affect
integrity via unknown vectors related to Libraries.
(CVE-2014-6512)

- Unspecified vulnerability in Oracle Java SE 5.0u71,
6u81, 7u67, and 8u20; Java SE Embedded 7u60; and JRockit
R27.8.3, and R28.3.3 allows remote attackers to affect
confidentiality and integrity via vectors related to
JSSE. (CVE-2014-6457)

- Unspecified vulnerability in Oracle Java SE 7u67 and
8u20 allows remote attackers to affect integrity via
unknown vectors related to Deployment, a different
vulnerability than CVE-2014-6476. (CVE-2014-6527)

- Unspecified vulnerability in Oracle Java SE 5.0u71,
6u81, 7u67, and 8u20, and Java SE Embedded 7u60, allows
remote attackers to affect integrity via unknown vectors
related to Libraries. (CVE-2014-6502)

- Unspecified vulnerability in Oracle Java SE 5.0u71,
6u81, 7u67, and 8u20; Java SE Embedded 7u60; and JRockit
R27.8.3 and JRockit R28.3.3 allows remote attackers to
affect integrity via unknown vectors related to
Security. (CVE-2014-6558)

More information can be found at
http://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update
_November_2014

See also :

https://bugzilla.novell.com/show_bug.cgi?id=904889
http://support.novell.com/security/cve/CVE-2014-3065.html
http://support.novell.com/security/cve/CVE-2014-3566.html
http://support.novell.com/security/cve/CVE-2014-4288.html
http://support.novell.com/security/cve/CVE-2014-6456.html
http://support.novell.com/security/cve/CVE-2014-6457.html
http://support.novell.com/security/cve/CVE-2014-6458.html
http://support.novell.com/security/cve/CVE-2014-6466.html
http://support.novell.com/security/cve/CVE-2014-6476.html
http://support.novell.com/security/cve/CVE-2014-6492.html
http://support.novell.com/security/cve/CVE-2014-6493.html
http://support.novell.com/security/cve/CVE-2014-6502.html
http://support.novell.com/security/cve/CVE-2014-6503.html
http://support.novell.com/security/cve/CVE-2014-6506.html
http://support.novell.com/security/cve/CVE-2014-6511.html
http://support.novell.com/security/cve/CVE-2014-6512.html
http://support.novell.com/security/cve/CVE-2014-6513.html
http://support.novell.com/security/cve/CVE-2014-6515.html
http://support.novell.com/security/cve/CVE-2014-6527.html
http://support.novell.com/security/cve/CVE-2014-6531.html
http://support.novell.com/security/cve/CVE-2014-6532.html
http://support.novell.com/security/cve/CVE-2014-6558.html

Solution :

Apply SAT patch number 9999.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now