Synopsis
The remote SUSE host is missing one or more security updates.
Description
This update fixes 13 security issues.
These security issues were fixed :
  - CVE-2015-0395: Unspecified vulnerability in Oracle Java     SE 5.0u75, 6u85, 7u72, and 8u25 allowed remote attackers     to affect confidentiality, integrity, and availability     via unknown vectors related to Hotspot (bnc#914041).
  - CVE-2015-0400: Unspecified vulnerability in Oracle Java     SE 6u85, 7u72, and 8u25 allowed remote attackers to     affect confidentiality via unknown vectors related to     Libraries (bnc#914041).
  - CVE-2015-0383: Unspecified vulnerability in Oracle Java     SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71     and 8u6; and JRockit R27.8.4 and R28.3.4 allowed local     users to affect integrity and availability via unknown     vectors related to Hotspot (bnc#914041).
  - CVE-2015-0412: Unspecified vulnerability in Oracle Java     SE 6u85, 7u72, and 8u25 allowed remote attackers to     affect confidentiality, integrity, and availability via     vectors related to JAX-WS (bnc#914041).
  - CVE-2015-0407: Unspecified vulnerability in Oracle Java     SE 5.0u75, 6u85, 7u72, and 8u25 allowed remote attackers     to affect confidentiality via unknown vectors related to     Swing (bnc#914041).
  - CVE-2015-0408: Unspecified vulnerability in Oracle Java     SE 5.0u75, 6u85, 7u72, and 8u25 allowed remote attackers     to affect confidentiality, integrity, and availability     via vectors related to RMI (bnc#914041).
  - CVE-2014-6585: Unspecified vulnerability in Oracle Java     SE 5.0u75, 6u85, 7u72, and 8u25 allowed remote attackers     to affect confidentiality via unknown vectors reelated     to 2D, a different vulnerability than CVE-2014-6591     (bnc#914041).
  - CVE-2014-6587: Unspecified vulnerability in Oracle Java     SE 6u85, 7u72, and 8u25 allowed local users to affect     confidentiality, integrity, and availability via unknown     vectors related to Libraries (bnc#914041).
  - CVE-2014-6591: Unspecified vulnerability in the Java SE     component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25     allowed remote attackers to affect confidentiality via     unknown vectors related to 2D, a different vulnerability     than CVE-2014-6585 (bnc#914041).
  - CVE-2014-6593: Unspecified vulnerability in Oracle Java     SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71     and 8u6; and JRockit 27.8.4 and 28.3.4 allowed remote     attackers to affect confidentiality and integrity via     vectors related to JSSE (bnc#914041).
  - CVE-2014-6601: Unspecified vulnerability in Oracle Java     SE 6u85, 7u72, and 8u25 allowed remote attackers to     affect confidentiality, integrity, and availability via     unknown vectors related to Hotspot (bnc#914041).
  - CVE-2015-0410: Unspecified vulnerability in the Java SE,     Java SE Embedded, JRockit component in Oracle Java SE     5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and     8u6; and JRockit R27.8.4 and R28.3.4 allowed remote     attackers to affect availability via unknown vectors     related to Security (bnc#914041).
  - CVE-2014-3566: The SSL protocol 3.0, as used in OpenSSL     through 1.0.1i and other products, used nondeterministic     CBC padding, which made it easier for man-in-the-middle     attackers to obtain cleartext data via a padding-oracle     attack, aka the 'POODLE' issue (bnc#901223).
The update package also includes non-security fixes. See advisory for details.
Note that Tenable Network Security has extracted the preceding description block directly from the SUSE security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
Solution
To install this SUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product :
SUSE Linux Enterprise Server 12 :
zypper in -t patch SUSE-SLE-SERVER-12-2015-122=1
SUSE Linux Enterprise Desktop 12 :
zypper in -t patch SUSE-SLE-DESKTOP-12-2015-122=1
To bring your system up-to-date, use 'zypper patch'.
Plugin Details
File Name: suse_SU-2015-0503-1.nasl
Agent: unix
Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C
Vulnerability Information
CPE: p-cpe:/a:novell:suse_linux:java-1_7_0-openjdk, p-cpe:/a:novell:suse_linux:java-1_7_0-openjdk-demo, p-cpe:/a:novell:suse_linux:java-1_7_0-openjdk-debugsource, p-cpe:/a:novell:suse_linux:java-1_7_0-openjdk-debuginfo, p-cpe:/a:novell:suse_linux:java-1_7_0-openjdk-headless, p-cpe:/a:novell:suse_linux:java-1_7_0-openjdk-devel-debuginfo, p-cpe:/a:novell:suse_linux:java-1_7_0-openjdk-devel, p-cpe:/a:novell:suse_linux:java-1_7_0-openjdk-headless-debuginfo, cpe:/o:novell:suse_linux:12, p-cpe:/a:novell:suse_linux:java-1_7_0-openjdk-demo-debuginfo
Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list
Exploit Ease: Exploits are available
Patch Publication Date: 3/9/2015
Vulnerability Publication Date: 10/15/2014
Reference Information
CVE: CVE-2014-3566, CVE-2014-6585, CVE-2014-6587, CVE-2014-6591, CVE-2014-6593, CVE-2014-6601, CVE-2015-0383, CVE-2015-0395, CVE-2015-0400, CVE-2015-0407, CVE-2015-0408, CVE-2015-0410, CVE-2015-0412
BID: 70574, 72132, 72136, 72140, 72142, 72155, 72159, 72162, 72165, 72168, 72169, 72173, 72175