RHEL 4 / 5 : java-1.5.0-ibm (RHSA-2008:0891)
High Nessus Plugin ID 40727
SynopsisThe remote Red Hat host is missing one or more security updates.
DescriptionUpdated java-1.5.0-ibm packages that fix a security issue are now available for Red Hat Enterprise Linux 4 Extras and 5 Supplementary.
This update has been rated as having moderate security impact by the Red Hat Security Response Team.
The IBM 1.5.0 Java release includes the IBM Java 2 Runtime Environment and the IBM Java 2 Software Development Kit.
A flaw was found in the Java Management Extensions (JMX) management agent. When local monitoring is enabled, remote attackers could use this flaw to perform illegal operations. (CVE-2008-3103)
All users of java-1.5.0-ibm are advised to upgrade to these updated packages containing the IBM 1.5.0 SR8a Java release, which resolves this issue.
SolutionUpdate the affected packages.