First published: Tue Feb 16 2021(Updated: )
IBM Java SE version 8 includes the IBM Java Runtime Environment and the IBM Java Software Development Kit.<br>This update upgrades IBM Java SE 8 to version 8 SR6-FP20.<br>Security Fix(es):<br><li> OpenJDK: Incomplete check for invalid characters in URI to path conversion (Libraries, 8242685) (CVE-2020-14797)</li> <li> OpenJDK: High memory usage during deserialization of Proxy class with many interfaces (Serialization, 8236862) (CVE-2020-14779)</li> <li> OpenJDK: Missing permission check in path to URI conversion (Libraries, 8242680) (CVE-2020-14796)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.8.0-ibm-1.8.0.6.20-1.el8_3 | 1.8.0-ibm-1.8.0.6.20-1.el8_3 |
redhat/java | <1.8.0-ibm-demo-1.8.0.6.20-1.el8_3 | 1.8.0-ibm-demo-1.8.0.6.20-1.el8_3 |
redhat/java | <1.8.0-ibm-devel-1.8.0.6.20-1.el8_3 | 1.8.0-ibm-devel-1.8.0.6.20-1.el8_3 |
redhat/java | <1.8.0-ibm-headless-1.8.0.6.20-1.el8_3 | 1.8.0-ibm-headless-1.8.0.6.20-1.el8_3 |
redhat/java | <1.8.0-ibm-jdbc-1.8.0.6.20-1.el8_3 | 1.8.0-ibm-jdbc-1.8.0.6.20-1.el8_3 |
redhat/java | <1.8.0-ibm-plugin-1.8.0.6.20-1.el8_3 | 1.8.0-ibm-plugin-1.8.0.6.20-1.el8_3 |
redhat/java | <1.8.0-ibm-src-1.8.0.6.20-1.el8_3 | 1.8.0-ibm-src-1.8.0.6.20-1.el8_3 |
redhat/java | <1.8.0-ibm-webstart-1.8.0.6.20-1.el8_3 | 1.8.0-ibm-webstart-1.8.0.6.20-1.el8_3 |
redhat/java | <1.8.0-ibm-1.8.0.6.20-1.el8_3 | 1.8.0-ibm-1.8.0.6.20-1.el8_3 |
redhat/java | <1.8.0-ibm-demo-1.8.0.6.20-1.el8_3 | 1.8.0-ibm-demo-1.8.0.6.20-1.el8_3 |
redhat/java | <1.8.0-ibm-devel-1.8.0.6.20-1.el8_3 | 1.8.0-ibm-devel-1.8.0.6.20-1.el8_3 |
redhat/java | <1.8.0-ibm-headless-1.8.0.6.20-1.el8_3 | 1.8.0-ibm-headless-1.8.0.6.20-1.el8_3 |
redhat/java | <1.8.0-ibm-jdbc-1.8.0.6.20-1.el8_3 | 1.8.0-ibm-jdbc-1.8.0.6.20-1.el8_3 |
redhat/java | <1.8.0-ibm-src-1.8.0.6.20-1.el8_3 | 1.8.0-ibm-src-1.8.0.6.20-1.el8_3 |
redhat/java | <1.8.0-ibm-1.8.0.6.20-1.el8_3 | 1.8.0-ibm-1.8.0.6.20-1.el8_3 |
redhat/java | <1.8.0-ibm-demo-1.8.0.6.20-1.el8_3 | 1.8.0-ibm-demo-1.8.0.6.20-1.el8_3 |
redhat/java | <1.8.0-ibm-devel-1.8.0.6.20-1.el8_3 | 1.8.0-ibm-devel-1.8.0.6.20-1.el8_3 |
redhat/java | <1.8.0-ibm-headless-1.8.0.6.20-1.el8_3 | 1.8.0-ibm-headless-1.8.0.6.20-1.el8_3 |
redhat/java | <1.8.0-ibm-jdbc-1.8.0.6.20-1.el8_3 | 1.8.0-ibm-jdbc-1.8.0.6.20-1.el8_3 |
redhat/java | <1.8.0-ibm-plugin-1.8.0.6.20-1.el8_3 | 1.8.0-ibm-plugin-1.8.0.6.20-1.el8_3 |
redhat/java | <1.8.0-ibm-src-1.8.0.6.20-1.el8_3 | 1.8.0-ibm-src-1.8.0.6.20-1.el8_3 |
redhat/java | <1.8.0-ibm-webstart-1.8.0.6.20-1.el8_3 | 1.8.0-ibm-webstart-1.8.0.6.20-1.el8_3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2021:0530 addresses an incomplete check for invalid characters in URI to path conversion in OpenJDK.
To resolve RHSA-2021:0530, you need to upgrade IBM Java SE to version 8 SR6-FP20.
RHSA-2021:0530 affects IBM Java SE version 8 up to 1.8.0-ibm-1.8.0.6.20-1.el8_3.
RHSA-2021:0530 contains security fixes that are critical to maintaining the integrity of systems using affected IBM Java versions.
The packages that need to be upgraded for RHSA-2021:0530 include java, java-demo, java-devel, java-headless, java-jdbc, java-plugin, java-src, and java-webstart.