First published: Thu Jun 11 2015(Updated: )
IBM Java SE version 6 includes the IBM Java Runtime Environment and the IBM<br>Java Software Development Kit.<br>This update corrects several security vulnerabilities in the IBM Java<br>Runtime Environment shipped as part of Red Hat Satellite 5. In a typical<br>operating environment, these are of low security risk as the runtime is not<br>used on untrusted applets. Further information about these flaws can be<br>found on the IBM Java Security alerts page, listed in the References<br>section. (CVE-2005-1080, CVE-2015-0138, CVE-2015-0192, CVE-2015-0458,<br>CVE-2015-0459, CVE-2015-0469, CVE-2015-0477, CVE-2015-0478, CVE-2015-0480,<br>CVE-2015-0488, CVE-2015-0491, CVE-2015-1914, CVE-2015-2808)<br>The CVE-2015-0478 issue was discovered by Florian Weimer of Red Hat<br>Product Security.<br>Note: With this update, the IBM JDK now disables RC4 SSL/TLS cipher suites<br>by default to address the CVE-2015-2808 issue. Refer to Red Hat Bugzilla<br>bug 1207101, linked to from the References section, for additional details<br>about this change.<br>Users of Red Hat Satellite 5.6 and 5.7 are advised to upgrade to these<br>updated packages, which contain the IBM Java SE 6 SR16-FP4 release. For<br>this update to take effect, Red Hat Satellite must be restarted<br>("/usr/sbin/rhn-satellite restart"), as well as all running instances of<br>IBM Java.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.6.0-ibm-1.6.0.16.4-1jpp.1.el6_6 | 1.6.0-ibm-1.6.0.16.4-1jpp.1.el6_6 |
redhat/java | <1.6.0-ibm-1.6.0.16.4-1jpp.1.el6_6 | 1.6.0-ibm-1.6.0.16.4-1jpp.1.el6_6 |
redhat/java | <1.6.0-ibm-devel-1.6.0.16.4-1jpp.1.el6_6 | 1.6.0-ibm-devel-1.6.0.16.4-1jpp.1.el6_6 |
redhat/java | <1.6.0-ibm-devel-1.6.0.16.4-1jpp.1.el6_6 | 1.6.0-ibm-devel-1.6.0.16.4-1jpp.1.el6_6 |
redhat/java | <1.6.0-ibm-1.6.0.16.4-1jpp.1.el5 | 1.6.0-ibm-1.6.0.16.4-1jpp.1.el5 |
redhat/java | <1.6.0-ibm-1.6.0.16.4-1jpp.1.el5 | 1.6.0-ibm-1.6.0.16.4-1jpp.1.el5 |
redhat/java | <1.6.0-ibm-devel-1.6.0.16.4-1jpp.1.el5 | 1.6.0-ibm-devel-1.6.0.16.4-1jpp.1.el5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.