Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.18.1.2025.0066.1
Categoría:openSUSE Local Security Checks
Título:openSUSE Security Advisory (openSUSE-SU-2025:0066-1)
Resumen:The remote host is missing an update for the 'java-11-openj9' package(s) announced via the openSUSE-SU-2025:0066-1 advisory.
Descripción:Summary:
The remote host is missing an update for the 'java-11-openj9' package(s) announced via the openSUSE-SU-2025:0066-1 advisory.

Vulnerability Insight:
This update for java-11-openj9 fixes the following issues:

- Update to OpenJDK 11.0.26 with OpenJ9 0.49.0 virtual machine
- Including Oracle October 2024 and January 2025 CPU changes
* CVE-2024-21208 (boo#1231702), CVE-2024-21210 (boo#1231711),
CVE-2024-21217 (boo#1231716), CVE-2024-21235 (boo#1231719),
CVE-2025-21502 (boo#1236278)
* OpenJ9 changes, see
[link moved to references]

- Update to OpenJDK 11.0.24 with OpenJ9 0.46.0 virtual machine
- Including Oracle July 2024 CPU changes
* CVE-2024-21131 (boo#1228046), CVE-2024-21138 (boo#1228047),
CVE-2024-21140 (boo#1228048), CVE-2024-21144 (boo#1228050),
CVE-2024-21147 (boo#1228052), CVE-2024-21145 (boo#1228051)
* OpenJ9 changes, see
[link moved to references]

- Update to OpenJDK 11.0.23 with OpenJ9 0.44.0 virtual machine
- Including Oracle April 2024 CPU changes
* CVE-2024-21012 (boo#1222987), CVE-2024-21094 (boo#1222986),
CVE-2024-21011 (boo#1222979), CVE-2024-21085 (boo#1222984),
CVE-2024-21068 (boo#1222983)
- Including OpenJ9/OMR specific fix:
* CVE-2024-3933 (boo#1225470)
* OpenJ9 changes, see
[link moved to references]

- Update to OpenJDK 11.0.22 with OpenJ9 0.43.0 virtual machine
- Including Oracle January 2024 CPU changes
* CVE-2024-20918 (boo#1218907), CVE-2024-20919 (boo#1218903),
CVE-2024-20921 (boo#1218905), CVE-2024-20926 (boo#1218906),
CVE-2024-20945 (boo#1218909), CVE-2024-20952 (boo#1218911)
* OpenJ9 changes, see
[link moved to references]
- Remove the possibility to put back removes JavaEE modules, since
our Java stack does not need this hack any more

- Update to OpenJDK 11.0.21 with OpenJ9 0.41.0 virtual machine
- Including Oracle October 2023 CPU changes
* CVE-2023-22081, boo#1216374
- Including Openj9 0.41.0 fixes of CVE-2023-5676, boo#1217214
* For other OpenJ9 changes, see
[link moved to references]

- Update to OpenJDK 11.0.20.1 with OpenJ9 0.40.0 virtual machine
* JDK-8313765: Invalid CEN header (invalid zip64 extra data
field size)

- Update to OpenJDK 11.0.20 with OpenJ9 0.40.0 virtual machine
- Including Oracle April 2023 CPU changes
* CVE-2023-22006 (boo#1213473), CVE-2023-22036 (boo#1213474),
CVE-2023-22041 (boo#1213475), CVE-2023-22045 (boo#1213481),
CVE-2023-22049 (boo#1213482), CVE-2023-25193 (boo#1207922)
* OpenJ9 changes, see
[link moved to references]

- Update to OpenJDK 11.0.19 with OpenJ9 0.38.0 virtual machine
- Including Oracle April 2023 CPU changes
* CVE-2023-21930 (boo#1210628), CVE-2023-21937 (boo#1210631),
CVE-2023-21938 (boo#1210632), CVE-2023-21939 (boo#1210634),
CVE-2023-21954 (boo#1210635), CVE-2023-21967 (boo#1210636),
CVE-2023-21968 (boo#1210637)
* OpenJ9 specific vulnerability: CVE-2023-2597 (boo#1211615)
* OpenJ9 changes, see
[link moved to references]

- Update to OpenJDK 11.0.18 with OpenJ9 0.36.1 virtual machine
* Including Oracle January 2023 CPU changes
+ CVE-2023-21835, boo#1207246
+ CVE-2023-21843, boo#1207248
* ... [Please see the references for more information on the vulnerabilities]

Affected Software/OS:
'java-11-openj9' package(s) on openSUSE Leap 15.6.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2020-14803
https://security.netapp.com/advisory/ntap-20201023-0004/
Debian Security Information: DSA-4779 (Google Search)
https://www.debian.org/security/2020/dsa-4779
https://security.gentoo.org/glsa/202101-19
https://www.oracle.com/security-alerts/cpujan2021.html
https://www.oracle.com/security-alerts/cpuoct2020.html
https://lists.debian.org/debian-lts-announce/2020/10/msg00031.html
SuSE Security Announcement: openSUSE-SU-2020:1893 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.html
Common Vulnerability Exposure (CVE) ID: CVE-2021-41041
https://bugs.eclipse.org/bugs/show_bug.cgi?id=579744
https://github.com/eclipse-openj9/openj9/pull/14935
Common Vulnerability Exposure (CVE) ID: CVE-2022-21426
Debian Security Information: DSA-5128 (Google Search)
https://www.debian.org/security/2022/dsa-5128
Debian Security Information: DSA-5131 (Google Search)
https://www.debian.org/security/2022/dsa-5131
https://www.oracle.com/security-alerts/cpuapr2022.html
https://lists.debian.org/debian-lts-announce/2022/05/msg00017.html
Common Vulnerability Exposure (CVE) ID: CVE-2022-21434
Common Vulnerability Exposure (CVE) ID: CVE-2022-21443
Common Vulnerability Exposure (CVE) ID: CVE-2022-21476
Common Vulnerability Exposure (CVE) ID: CVE-2022-21496
Common Vulnerability Exposure (CVE) ID: CVE-2022-21540
Debian Security Information: DSA-5188 (Google Search)
https://www.debian.org/security/2022/dsa-5188
Debian Security Information: DSA-5192 (Google Search)
https://www.debian.org/security/2022/dsa-5192
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KO3DXNKZ4EU3UZBT6AAR4XRKCD73KLMO/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L3XPOTPPBZIPFBZHQE5E7OW6PDACUMCJ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JN3EVGR7FD3ZLV5SBTJXUIDCMSK4QUE2/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H4YNJSJ64NPCNKFPNBYITNZU5H3L4D6L/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I5OZNAZJ4YHLOKRRRZSWRT5OJ25E4XLM/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YULPNO3PAWMEQQZV2C54I3H3ZOXFZUTB/
https://security.gentoo.org/glsa/202401-25
https://www.oracle.com/security-alerts/cpujul2022.html
Common Vulnerability Exposure (CVE) ID: CVE-2022-21541
Common Vulnerability Exposure (CVE) ID: CVE-2022-21618
FEDORA-2022-1c07902a5e
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QLQ7OD33W6LT3HWI7VYDFFJLV75Y73K/
FEDORA-2022-5d494ab9ab
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/37QDWJBGEPP65X43NXQTXQ7KASLUHON6/
FEDORA-2022-d989953883
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ARF4QF4N3X5GSFHXUBWARGLISGKJ33R/
FEDORA-2022-f76014ae17
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EXSBV3W6EP6B7XJ63Z2FPVBH6HAPGJ5T/
https://security.netapp.com/advisory/ntap-20221028-0012/
https://www.oracle.com/security-alerts/cpuoct2022.html
Common Vulnerability Exposure (CVE) ID: CVE-2022-21619
FEDORA-2022-361f34f2a9
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HNGMDNIHAA73BEX6XPA2IMXJSGOKKYE6/
FEDORA-2022-b050ae8974
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PB3CIGOFG7CENUVVE4FFZT2HI5FO77XU/
Common Vulnerability Exposure (CVE) ID: CVE-2022-21624
Common Vulnerability Exposure (CVE) ID: CVE-2022-21626
Common Vulnerability Exposure (CVE) ID: CVE-2022-21628
Common Vulnerability Exposure (CVE) ID: CVE-2022-34169
DSA-5188
DSA-5192
DSA-5256
https://www.debian.org/security/2022/dsa-5256
FEDORA-2022-19b6f21746
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KO3DXNKZ4EU3UZBT6AAR4XRKCD73KLMO/
FEDORA-2022-80afe2304a
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L3XPOTPPBZIPFBZHQE5E7OW6PDACUMCJ/
FEDORA-2022-ae563934f7
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JN3EVGR7FD3ZLV5SBTJXUIDCMSK4QUE2/
FEDORA-2022-b76ab52e73
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H4YNJSJ64NPCNKFPNBYITNZU5H3L4D6L/
FEDORA-2022-d26586b419
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I5OZNAZJ4YHLOKRRRZSWRT5OJ25E4XLM/
FEDORA-2022-e573851f56
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YULPNO3PAWMEQQZV2C54I3H3ZOXFZUTB/
[debian-lts-announce] 20221018 [SECURITY] [DLA 3155-1] bcel security update
https://lists.debian.org/debian-lts-announce/2022/10/msg00024.html
[oss-security] 20220719 CVE-2022-34169: Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets
http://www.openwall.com/lists/oss-security/2022/07/19/5
[oss-security] 20220719 Re: CVE-2022-34169: Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets
http://www.openwall.com/lists/oss-security/2022/07/19/6
http://www.openwall.com/lists/oss-security/2022/07/20/2
[oss-security] 20220720 Re: CVE-2022-34169: Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets
http://www.openwall.com/lists/oss-security/2022/07/20/3
[oss-security] 20221017 Re: CVE-2022-34169: Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets
http://www.openwall.com/lists/oss-security/2022/10/18/2
[oss-security] 20221104 Re: CVE-2022-42920: Apache Commons BCEL prior to 6.6.0 allows producing arbitrary bytecode via out-of-bounds writing
http://www.openwall.com/lists/oss-security/2022/11/04/8
[oss-security] 20221107 Re: CVE-2022-42920: Apache Commons BCEL prior to 6.6.0 allows producing arbitrary bytecode via out-of-bounds writing
http://www.openwall.com/lists/oss-security/2022/11/07/2
http://packetstormsecurity.com/files/168186/Xalan-J-XSLTC-Integer-Truncation.html
https://lists.apache.org/thread/12pxy4phsry6c34x2ol4fft6xlho4kyw
https://lists.apache.org/thread/2qvl7r43wb4t8p9dd9om1bnkssk07sn8
https://security.netapp.com/advisory/ntap-20220729-0009/
Common Vulnerability Exposure (CVE) ID: CVE-2022-3676
https://github.com/eclipse-openj9/openj9/pull/16122
https://github.com/eclipse/omr/pull/6773
https://gitlab.eclipse.org/eclipsefdn/emo-team/emo/-/issues/389
Common Vulnerability Exposure (CVE) ID: CVE-2022-39399
Common Vulnerability Exposure (CVE) ID: CVE-2023-21835
Oracle Advisory
https://www.oracle.com/security-alerts/cpujan2023.html
Common Vulnerability Exposure (CVE) ID: CVE-2023-21843
Common Vulnerability Exposure (CVE) ID: CVE-2023-21930
Debian Security Information: DSA-5430 (Google Search)
https://www.debian.org/security/2023/dsa-5430
Debian Security Information: DSA-5478 (Google Search)
https://www.debian.org/security/2023/dsa-5478
https://www.couchbase.com/alerts/
https://www.oracle.com/security-alerts/cpuapr2023.html
https://lists.debian.org/debian-lts-announce/2023/09/msg00018.html
Common Vulnerability Exposure (CVE) ID: CVE-2023-21937
Common Vulnerability Exposure (CVE) ID: CVE-2023-21938
Common Vulnerability Exposure (CVE) ID: CVE-2023-21939
Common Vulnerability Exposure (CVE) ID: CVE-2023-21954
Common Vulnerability Exposure (CVE) ID: CVE-2023-21967
Common Vulnerability Exposure (CVE) ID: CVE-2023-21968
Common Vulnerability Exposure (CVE) ID: CVE-2023-22006
Debian Security Information: DSA-5458 (Google Search)
https://www.debian.org/security/2023/dsa-5458
https://www.oracle.com/security-alerts/cpujul2023.html
Common Vulnerability Exposure (CVE) ID: CVE-2023-22036
Common Vulnerability Exposure (CVE) ID: CVE-2023-22041
Common Vulnerability Exposure (CVE) ID: CVE-2023-22045
Common Vulnerability Exposure (CVE) ID: CVE-2023-22049
Common Vulnerability Exposure (CVE) ID: CVE-2023-22081
https://www.oracle.com/security-alerts/cpuoct2023.html
https://lists.debian.org/debian-lts-announce/2023/10/msg00041.html
https://security.netapp.com/advisory/ntap-20231027-0006/
https://www.debian.org/security/2023/dsa-5537
https://www.debian.org/security/2023/dsa-5548
Common Vulnerability Exposure (CVE) ID: CVE-2023-25193
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KWCHWSICWVZSAXP2YAXM65JC2GR53547/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YZ5M2GSAIHFPLHYJXUPQ2QDJCLWXUGO3/
https://chromium.googlesource.com/chromium/src/+/e1f324aa681af54101c1f2d173d92adb80e37088/DEPS#361
https://github.com/harfbuzz/harfbuzz/blob/2822b589bc837fae6f66233e2cf2eef0f6ce8470/src/hb-ot-layout-gsubgpos.hh
https://github.com/harfbuzz/harfbuzz/commit/85be877925ddbf34f74a1229f3ca1716bb6170dc
Common Vulnerability Exposure (CVE) ID: CVE-2023-2597
https://github.com/eclipse-openj9/openj9/pull/17259
Common Vulnerability Exposure (CVE) ID: CVE-2023-5676
https://github.com/eclipse-openj9/openj9/pull/18085
https://gitlab.eclipse.org/security/cve-assignement/-/issues/13
Common Vulnerability Exposure (CVE) ID: CVE-2024-20918
https://www.oracle.com/security-alerts/cpujan2024.html
https://lists.debian.org/debian-lts-announce/2024/01/msg00023.html
Common Vulnerability Exposure (CVE) ID: CVE-2024-20919
Common Vulnerability Exposure (CVE) ID: CVE-2024-20921
Common Vulnerability Exposure (CVE) ID: CVE-2024-20926
Common Vulnerability Exposure (CVE) ID: CVE-2024-20945
Common Vulnerability Exposure (CVE) ID: CVE-2024-20952
Common Vulnerability Exposure (CVE) ID: CVE-2024-21011
https://www.oracle.com/security-alerts/cpuapr2024.html
https://lists.debian.org/debian-lts-announce/2024/04/msg00014.html
Common Vulnerability Exposure (CVE) ID: CVE-2024-21012
Common Vulnerability Exposure (CVE) ID: CVE-2024-21068
Common Vulnerability Exposure (CVE) ID: CVE-2024-21085
Common Vulnerability Exposure (CVE) ID: CVE-2024-21094
Common Vulnerability Exposure (CVE) ID: CVE-2024-21131
Common Vulnerability Exposure (CVE) ID: CVE-2024-21138
Common Vulnerability Exposure (CVE) ID: CVE-2024-21140
Common Vulnerability Exposure (CVE) ID: CVE-2024-21144
Common Vulnerability Exposure (CVE) ID: CVE-2024-21145
Common Vulnerability Exposure (CVE) ID: CVE-2024-21147
Common Vulnerability Exposure (CVE) ID: CVE-2024-21208
Common Vulnerability Exposure (CVE) ID: CVE-2024-21210
Common Vulnerability Exposure (CVE) ID: CVE-2024-21217
Common Vulnerability Exposure (CVE) ID: CVE-2024-21235
Common Vulnerability Exposure (CVE) ID: CVE-2024-3933
https://github.com/eclipse/omr/pull/7275
https://gitlab.eclipse.org/security/cve-assignement/-/issues/21
Common Vulnerability Exposure (CVE) ID: CVE-2025-21502
CopyrightCopyright (C) 2025 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.