RHEL 5 / 6 : Red Hat Satellite IBM Java Runtime (RHSA-2015:1091)

critical Nessus Plugin ID 84143

Synopsis

The remote Red Hat host is missing one or more security updates for Red Hat Satellite IBM Java Runtime.

Description

The remote Redhat Enterprise Linux 5 / 6 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2015:1091 advisory.

IBM Java SE version 6 includes the IBM Java Runtime Environment and the IBM Java Software Development Kit.

This update corrects several security vulnerabilities in the IBM Java Runtime Environment shipped as part of Red Hat Satellite 5. In a typical operating environment, these are of low security risk as the runtime is not used on untrusted applets. Further information about these flaws can be found on the IBM Java Security alerts page, listed in the References section. (CVE-2005-1080, CVE-2015-0138, CVE-2015-0192, CVE-2015-0458, CVE-2015-0459, CVE-2015-0469, CVE-2015-0477, CVE-2015-0478, CVE-2015-0480, CVE-2015-0488, CVE-2015-0491, CVE-2015-1914, CVE-2015-2808)

The CVE-2015-0478 issue was discovered by Florian Weimer of Red Hat Product Security.

Note: With this update, the IBM JDK now disables RC4 SSL/TLS cipher suites by default to address the CVE-2015-2808 issue. Refer to Red Hat Bugzilla bug 1207101, linked to from the References section, for additional details about this change.

Users of Red Hat Satellite 5.6 and 5.7 are advised to upgrade to these updated packages, which contain the IBM Java SE 6 SR16-FP4 release. For this update to take effect, Red Hat Satellite must be restarted (/usr/sbin/rhn-satellite restart), as well as all running instances of IBM Java.

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the RHEL Red Hat Satellite IBM Java Runtime package based on the guidance in RHSA-2015:1091.

See Also

http://www.nessus.org/u?d3f52143

https://www.ibm.com/developerworks/java/jdk/alerts/

https://bugzilla.redhat.com/show_bug.cgi?id=1207101#c4

https://bugzilla.redhat.com/show_bug.cgi?id=1210355

https://bugzilla.redhat.com/show_bug.cgi?id=1210829

https://bugzilla.redhat.com/show_bug.cgi?id=1211299

https://bugzilla.redhat.com/show_bug.cgi?id=1211504

https://bugzilla.redhat.com/show_bug.cgi?id=1211543

https://bugzilla.redhat.com/show_bug.cgi?id=1211768

https://bugzilla.redhat.com/show_bug.cgi?id=1211769

https://bugzilla.redhat.com/show_bug.cgi?id=1211771

https://bugzilla.redhat.com/show_bug.cgi?id=1219212

https://bugzilla.redhat.com/show_bug.cgi?id=1219215

https://bugzilla.redhat.com/show_bug.cgi?id=1219223

https://bugzilla.redhat.com/show_bug.cgi?id=606442

https://access.redhat.com/errata/RHSA-2015:1091

https://access.redhat.com/security/updates/classification/#low

https://bugzilla.redhat.com/show_bug.cgi?id=1207101

Plugin Details

Severity: Critical

ID: 84143

File Name: redhat-RHSA-2015-1091.nasl

Version: 2.14

Type: local

Agent: unix

Published: 6/12/2015

Updated: 11/4/2024

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.4

Vendor

Vendor Severity: Low

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2015-0491

CVSS v3

Risk Factor: Critical

Base Score: 10

Temporal Score: 9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2015-2808

Vulnerability Information

CPE: cpe:/o:redhat:enterprise_linux:5, cpe:/o:redhat:enterprise_linux:6, p-cpe:/a:redhat:enterprise_linux:java-1.6.0-ibm, p-cpe:/a:redhat:enterprise_linux:java-1.6.0-ibm-devel

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 6/11/2015

Vulnerability Publication Date: 5/2/2005

Reference Information

CVE: CVE-2005-1080, CVE-2015-0138, CVE-2015-0192, CVE-2015-0458, CVE-2015-0459, CVE-2015-0469, CVE-2015-0477, CVE-2015-0478, CVE-2015-0480, CVE-2015-0488, CVE-2015-0491, CVE-2015-1914, CVE-2015-2808

CWE: 122, 22, 248, 327, 358

RHSA: 2015:1091