First published: Wed May 20 2015(Updated: )
IBM Java SE version 7 Release 1 includes the IBM Java Runtime Environment<br>and the IBM Java Software Development Kit.<br>This update fixes several vulnerabilities in the IBM Java Runtime<br>Environment and the IBM Java Software Development Kit. Further information<br>about these flaws can be found on the IBM Java Security alerts page, listed<br>in the References section. (CVE-2005-1080, CVE-2015-0138, CVE-2015-0192,<br>CVE-2015-0458, CVE-2015-0459, CVE-2015-0469, CVE-2015-0477, CVE-2015-0478,<br>CVE-2015-0480, CVE-2015-0488, CVE-2015-0491, CVE-2015-1914, CVE-2015-2808)<br>The CVE-2015-0478 issue was discovered by Florian Weimer of Red Hat<br>Product Security.<br>Note: With this update, the IBM JDK now disables RC4 SSL/TLS cipher suites<br>by default to address the CVE-2015-2808 issue. Refer to Red Hat Bugzilla<br>bug 1207101, linked to in the References section, for additional details<br>about this change.<br>All users of java-1.7.1-ibm are advised to upgrade to these updated<br>packages, containing the IBM Java SE 7R1 SR3 release. All running instances<br>of IBM Java must be restarted for the update to take effect.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.7.1-ibm-1.7.1.3.0-1jpp.2.el7_1 | 1.7.1-ibm-1.7.1.3.0-1jpp.2.el7_1 |
redhat/java | <1.7.1-ibm-1.7.1.3.0-1jpp.2.el7_1 | 1.7.1-ibm-1.7.1.3.0-1jpp.2.el7_1 |
redhat/java | <1.7.1-ibm-demo-1.7.1.3.0-1jpp.2.el7_1 | 1.7.1-ibm-demo-1.7.1.3.0-1jpp.2.el7_1 |
redhat/java | <1.7.1-ibm-devel-1.7.1.3.0-1jpp.2.el7_1 | 1.7.1-ibm-devel-1.7.1.3.0-1jpp.2.el7_1 |
redhat/java | <1.7.1-ibm-devel-1.7.1.3.0-1jpp.2.el7_1 | 1.7.1-ibm-devel-1.7.1.3.0-1jpp.2.el7_1 |
redhat/java | <1.7.1-ibm-jdbc-1.7.1.3.0-1jpp.2.el7_1 | 1.7.1-ibm-jdbc-1.7.1.3.0-1jpp.2.el7_1 |
redhat/java | <1.7.1-ibm-plugin-1.7.1.3.0-1jpp.2.el7_1 | 1.7.1-ibm-plugin-1.7.1.3.0-1jpp.2.el7_1 |
redhat/java | <1.7.1-ibm-src-1.7.1.3.0-1jpp.2.el7_1 | 1.7.1-ibm-src-1.7.1.3.0-1jpp.2.el7_1 |
redhat/java | <1.7.1-ibm-1.7.1.3.0-1jpp.2.el6_6 | 1.7.1-ibm-1.7.1.3.0-1jpp.2.el6_6 |
redhat/java | <1.7.1-ibm-1.7.1.3.0-1jpp.2.el6_6 | 1.7.1-ibm-1.7.1.3.0-1jpp.2.el6_6 |
redhat/java | <1.7.1-ibm-demo-1.7.1.3.0-1jpp.2.el6_6 | 1.7.1-ibm-demo-1.7.1.3.0-1jpp.2.el6_6 |
redhat/java | <1.7.1-ibm-devel-1.7.1.3.0-1jpp.2.el6_6 | 1.7.1-ibm-devel-1.7.1.3.0-1jpp.2.el6_6 |
redhat/java | <1.7.1-ibm-devel-1.7.1.3.0-1jpp.2.el6_6 | 1.7.1-ibm-devel-1.7.1.3.0-1jpp.2.el6_6 |
redhat/java | <1.7.1-ibm-jdbc-1.7.1.3.0-1jpp.2.el6_6 | 1.7.1-ibm-jdbc-1.7.1.3.0-1jpp.2.el6_6 |
redhat/java | <1.7.1-ibm-plugin-1.7.1.3.0-1jpp.2.el6_6 | 1.7.1-ibm-plugin-1.7.1.3.0-1jpp.2.el6_6 |
redhat/java | <1.7.1-ibm-src-1.7.1.3.0-1jpp.2.el6_6 | 1.7.1-ibm-src-1.7.1.3.0-1jpp.2.el6_6 |
redhat/java | <1.7.1-ibm-demo-1.7.1.3.0-1jpp.2.el6_6 | 1.7.1-ibm-demo-1.7.1.3.0-1jpp.2.el6_6 |
redhat/java | <1.7.1-ibm-jdbc-1.7.1.3.0-1jpp.2.el6_6 | 1.7.1-ibm-jdbc-1.7.1.3.0-1jpp.2.el6_6 |
redhat/java | <1.7.1-ibm-plugin-1.7.1.3.0-1jpp.2.el6_6 | 1.7.1-ibm-plugin-1.7.1.3.0-1jpp.2.el6_6 |
redhat/java | <1.7.1-ibm-src-1.7.1.3.0-1jpp.2.el6_6 | 1.7.1-ibm-src-1.7.1.3.0-1jpp.2.el6_6 |
redhat/java | <1.7.1-ibm-demo-1.7.1.3.0-1jpp.2.el7_1 | 1.7.1-ibm-demo-1.7.1.3.0-1jpp.2.el7_1 |
redhat/java | <1.7.1-ibm-jdbc-1.7.1.3.0-1jpp.2.el7_1 | 1.7.1-ibm-jdbc-1.7.1.3.0-1jpp.2.el7_1 |
redhat/java | <1.7.1-ibm-src-1.7.1.3.0-1jpp.2.el7_1 | 1.7.1-ibm-src-1.7.1.3.0-1jpp.2.el7_1 |
redhat/java | <1.7.1-ibm-plugin-1.7.1.3.0-1jpp.2.el7_1 | 1.7.1-ibm-plugin-1.7.1.3.0-1jpp.2.el7_1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.