Bug 1214431 - VUL-0: java-1_8_0-ibm: IBM Security Update August 2023
Summary: VUL-0: java-1_8_0-ibm: IBM Security Update August 2023
Status: RESOLVED FIXED
Alias: None
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks: 1216824
  Show dependency treegraph
 
Reported: 2023-08-21 08:57 UTC by Pedro Monreal Gonzalez
Modified: 2023-11-02 14:09 UTC (History)
6 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Pedro Monreal Gonzalez 2023-08-21 08:57:00 UTC
A new IBM security advisory has been released, see [0]. This advisory mentions 
CVE-2022-40609 as being fixed in a previously released version of java-1_8_0-ibm, namely version 8.0.8.5. Since this version has been released I will just mention this CVE as a new entry in the changelog.

Note that, this CVE in the openjdk version is tracked in bsc#1213934.

[0] https://www.ibm.com/support/pages/java-sdk-security-vulnerabilities#IBM_Security_Update_August_2023
Comment 1 Pedro Monreal Gonzalez 2023-08-21 09:20:27 UTC
I'm adding IBM and Mark Cowley in CC just for awareness. No action from IBM is required at this point. TIA.
Comment 4 Maintenance Automation 2023-08-23 20:30:09 UTC
SUSE-SU-2023:3406-1: An update that solves eight vulnerabilities can now be installed.

Category: security (important)
Bug References: 1214431
CVE References: CVE-2022-40609, CVE-2023-22006, CVE-2023-22036, CVE-2023-22041, CVE-2023-22044, CVE-2023-22045, CVE-2023-22049, CVE-2023-25193
Sources used:

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 5 Maintenance Automation 2023-08-28 08:30:04 UTC
SUSE-SU-2023:3441-1: An update that solves eight vulnerabilities and has two fixes can now be installed.

Category: security (important)
Bug References: 1207922, 1213473, 1213474, 1213475, 1213479, 1213481, 1213482, 1213541, 1213934, 1214431
CVE References: CVE-2022-40609, CVE-2023-22006, CVE-2023-22036, CVE-2023-22041, CVE-2023-22044, CVE-2023-22045, CVE-2023-22049, CVE-2023-25193
Sources used:

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Marcus Meissner 2023-10-18 12:45:31 UTC
done
Comment 10 Steven Moring 2023-10-18 12:57:27 UTC
(In reply to Marcus Meissner from comment #9)
> done

I'm not sure how I'm missing this.

https://scc.suse.com/patches#!/257437

Customer must not be downloading to their RMT servers as frequently as they need to be.