First published: Thu Mar 04 2021(Updated: )
IBM Java SE version 8 includes the IBM Java Runtime Environment and the IBM Java Software Development Kit.<br>This update upgrades IBM Java SE 8 to version 8 SR6-FP25.<br>Security Fix(es):<br><li> IBM JDK: Stack-based buffer overflow when converting from UTF-8 characters to platform encoding (CVE-2020-27221)</li> <li> OpenJDK: Unexpected exceptions raised by DOMKeyInfoFactory and DOMXMLSignatureFactory (Security, 8231415) (CVE-2020-2773)</li> <li> OpenJDK: Credentials sent over unencrypted LDAP connection (JNDI, 8237990) (CVE-2020-14781)</li> <li> OpenJDK: Certificate blacklist bypass via alternate certificate encodings (Libraries, 8237995) (CVE-2020-14782)</li> <li> OpenJDK: Race condition in NIO Buffer boundary checks (Libraries, 8244136) (CVE-2020-14803)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.8.0-ibm-1.8.0.6.25-2.el8_3 | 1.8.0-ibm-1.8.0.6.25-2.el8_3 |
redhat/java | <1.8.0-ibm-demo-1.8.0.6.25-2.el8_3 | 1.8.0-ibm-demo-1.8.0.6.25-2.el8_3 |
redhat/java | <1.8.0-ibm-devel-1.8.0.6.25-2.el8_3 | 1.8.0-ibm-devel-1.8.0.6.25-2.el8_3 |
redhat/java | <1.8.0-ibm-headless-1.8.0.6.25-2.el8_3 | 1.8.0-ibm-headless-1.8.0.6.25-2.el8_3 |
redhat/java | <1.8.0-ibm-jdbc-1.8.0.6.25-2.el8_3 | 1.8.0-ibm-jdbc-1.8.0.6.25-2.el8_3 |
redhat/java | <1.8.0-ibm-plugin-1.8.0.6.25-2.el8_3 | 1.8.0-ibm-plugin-1.8.0.6.25-2.el8_3 |
redhat/java | <1.8.0-ibm-src-1.8.0.6.25-2.el8_3 | 1.8.0-ibm-src-1.8.0.6.25-2.el8_3 |
redhat/java | <1.8.0-ibm-webstart-1.8.0.6.25-2.el8_3 | 1.8.0-ibm-webstart-1.8.0.6.25-2.el8_3 |
redhat/java | <1.8.0-ibm-1.8.0.6.25-2.el8_3 | 1.8.0-ibm-1.8.0.6.25-2.el8_3 |
redhat/java | <1.8.0-ibm-demo-1.8.0.6.25-2.el8_3 | 1.8.0-ibm-demo-1.8.0.6.25-2.el8_3 |
redhat/java | <1.8.0-ibm-devel-1.8.0.6.25-2.el8_3 | 1.8.0-ibm-devel-1.8.0.6.25-2.el8_3 |
redhat/java | <1.8.0-ibm-headless-1.8.0.6.25-2.el8_3 | 1.8.0-ibm-headless-1.8.0.6.25-2.el8_3 |
redhat/java | <1.8.0-ibm-jdbc-1.8.0.6.25-2.el8_3 | 1.8.0-ibm-jdbc-1.8.0.6.25-2.el8_3 |
redhat/java | <1.8.0-ibm-src-1.8.0.6.25-2.el8_3 | 1.8.0-ibm-src-1.8.0.6.25-2.el8_3 |
redhat/java | <1.8.0-ibm-1.8.0.6.25-2.el8_3 | 1.8.0-ibm-1.8.0.6.25-2.el8_3 |
redhat/java | <1.8.0-ibm-demo-1.8.0.6.25-2.el8_3 | 1.8.0-ibm-demo-1.8.0.6.25-2.el8_3 |
redhat/java | <1.8.0-ibm-devel-1.8.0.6.25-2.el8_3 | 1.8.0-ibm-devel-1.8.0.6.25-2.el8_3 |
redhat/java | <1.8.0-ibm-headless-1.8.0.6.25-2.el8_3 | 1.8.0-ibm-headless-1.8.0.6.25-2.el8_3 |
redhat/java | <1.8.0-ibm-jdbc-1.8.0.6.25-2.el8_3 | 1.8.0-ibm-jdbc-1.8.0.6.25-2.el8_3 |
redhat/java | <1.8.0-ibm-plugin-1.8.0.6.25-2.el8_3 | 1.8.0-ibm-plugin-1.8.0.6.25-2.el8_3 |
redhat/java | <1.8.0-ibm-src-1.8.0.6.25-2.el8_3 | 1.8.0-ibm-src-1.8.0.6.25-2.el8_3 |
redhat/java | <1.8.0-ibm-webstart-1.8.0.6.25-2.el8_3 | 1.8.0-ibm-webstart-1.8.0.6.25-2.el8_3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.