Bug 1216640

Summary: VUL-0: java-1_8_0-ibm: IBM Security Update October 2023
Product: [Novell Products] SUSE Security Incidents Reporter: Pedro Monreal Gonzalez <pmonrealgonzalez>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: IN_PROGRESS --- QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: gery.schneider, mcowley, meissner, pmonrealgonzalez, tstaudt
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/383276/
Whiteboard:
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Pedro Monreal Gonzalez 2023-10-27 08:41:03 UTC
A new security advisory has been published for IBM Java, see:
>  * https://www.ibm.com/support/pages/java-sdk-security-vulnerabilities#Oracle_October_17_2023_CPU

The fixes for the following CVEs will be included in the next version:
  * CVE-2023-22081
  * CVE-2023-22067
  * CVE-2023-22025

I'll update to the new version once released.
Comment 1 Pedro Monreal Gonzalez 2023-10-27 09:36:51 UTC
I'm adding IBM and Mark Cowley in CC just for awareness. No action from IBM is required at this point. TIA.
Comment 2 Pedro Monreal Gonzalez 2023-10-27 12:09:28 UTC
See also: https://www.oracle.com/security-alerts/cpuoct2023.html#AppendixJAVA
Comment 4 Maintenance Automation 2023-11-27 12:30:53 UTC
SUSE-SU-2023:4572-1: An update that solves four vulnerabilities and has two security fixes can now be installed.

Category: security (important)
Bug References: 1204264, 1216339, 1216374, 1216379, 1216640, 1217214
CVE References: CVE-2023-22025, CVE-2023-22067, CVE-2023-22081, CVE-2023-5676
Sources used:

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 5 Maintenance Automation 2023-11-29 16:30:01 UTC
SUSE-SU-2023:4614-1: An update that solves four vulnerabilities and has two security fixes can now be installed.

Category: security (important)
Bug References: 1204264, 1216339, 1216374, 1216379, 1216640, 1217214
CVE References: CVE-2023-22025, CVE-2023-22067, CVE-2023-22081, CVE-2023-5676
Sources used:

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.