Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality via vectors related to JAX-WS. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to improper restriction of com.sun.xml.internal packages and "Better handling of UI elements."
This security problem affects also IBM Java on SUSE Linux Enterprise Server in various versions.
IBM is still working on a fix currently. As soon as a fix is provided we will be shipping updated IBM Java packages.
for more information and the current IBM status.
| Product(s) | Fixed package version(s) | References |
| SUSE Linux Enterprise Server 10 SP3 LTSS for x86 | java-1_6_0-ibm >= 1.6.0_sr13.0-0.7.7.1 java-1_6_0-ibm-alsa >= 1.6.0_sr13.0-0.7.7.1 java-1_6_0-ibm-devel >= 1.6.0_sr13.0-0.7.7.1 java-1_6_0-ibm-fonts >= 1.6.0_sr13.0-0.7.7.1 java-1_6_0-ibm-jdbc >= 1.6.0_sr13.0-0.7.7.1 java-1_6_0-ibm-plugin >= 1.6.0_sr13.0-0.7.7.1
| Builds ZYPP Patch Nr: 8497 |
| SUSE Linux Enterprise Server 10 SP3 LTSS for IBM zSeries 64bit | java-1_6_0-ibm >= 1.6.0_sr13.0-0.7.7.1 java-1_6_0-ibm-32bit >= 1.6.0_sr13.0-0.7.7.1 java-1_6_0-ibm-devel >= 1.6.0_sr13.0-0.7.7.1 java-1_6_0-ibm-devel-32bit >= 1.6.0_sr13.0-0.7.7.1 java-1_6_0-ibm-fonts >= 1.6.0_sr13.0-0.7.7.1 java-1_6_0-ibm-jdbc >= 1.6.0_sr13.0-0.7.7.1
| Builds ZYPP Patch Nr: 8497 |
| SUSE Linux Enterprise Server 10 SP3 LTSS for AMD64 and Intel EM64T | java-1_6_0-ibm >= 1.6.0_sr13.0-0.7.7.1 java-1_6_0-ibm-32bit >= 1.6.0_sr13.0-0.7.7.1 java-1_6_0-ibm-alsa-32bit >= 1.6.0_sr13.0-0.7.7.1 java-1_6_0-ibm-devel >= 1.6.0_sr13.0-0.7.7.1 java-1_6_0-ibm-devel-32bit >= 1.6.0_sr13.0-0.7.7.1 java-1_6_0-ibm-fonts >= 1.6.0_sr13.0-0.7.7.1 java-1_6_0-ibm-jdbc >= 1.6.0_sr13.0-0.7.7.1 java-1_6_0-ibm-plugin >= 1.6.0_sr13.0-0.7.7.1 java-1_6_0-ibm-plugin-32bit >= 1.6.0_sr13.0-0.7.7.1
| Builds ZYPP Patch Nr: 8497 |
| SLE 11 SP2 DEBUGINFO | java-1_6_0-openjdk-debuginfo >= 1.6.0.0_b27.1.12.2-0.2.1 java-1_6_0-openjdk-debugsource >= 1.6.0.0_b27.1.12.2-0.2.1
| Builds SAT Patch Nr: 7332 |
| SUSE Linux Enterprise Desktop 11 SP2 | java-1_6_0-openjdk >= 1.6.0.0_b27.1.12.2-0.2.1 java-1_6_0-openjdk-demo >= 1.6.0.0_b27.1.12.2-0.2.1 java-1_6_0-openjdk-devel >= 1.6.0.0_b27.1.12.2-0.2.1
| Builds SAT Patch Nr: 7332 |
SUSE Linux Enterprise Server 11 SP1 LTSS SUSE Linux Enterprise Server 11 SP1 for VMware LTSS | java-1_6_0-ibm >= 1.6.0_sr13.0-0.8.1 java-1_6_0-ibm-alsa >= 1.6.0_sr13.0-0.8.1 java-1_6_0-ibm-fonts >= 1.6.0_sr13.0-0.8.1 java-1_6_0-ibm-jdbc >= 1.6.0_sr13.0-0.8.1 java-1_6_0-ibm-plugin >= 1.6.0_sr13.0-0.8.1
| Builds SAT Patch Nr: 7482 |
| SUSE Linux Enterprise Server 11 SP1 LTSS | java-1_6_0-ibm >= 1.6.0_sr13.0-0.8.1 java-1_6_0-ibm-fonts >= 1.6.0_sr13.0-0.8.1 java-1_6_0-ibm-jdbc >= 1.6.0_sr13.0-0.8.1
| Builds SAT Patch Nr: 7482 |
SUSE Linux Enterprise Server 11 SP1 LTSS SUSE Linux Enterprise Server 11 SP1 for VMware LTSS | java-1_6_0-ibm >= 1.6.0_sr13.0-0.8.1 java-1_6_0-ibm-fonts >= 1.6.0_sr13.0-0.8.1 java-1_6_0-ibm-jdbc >= 1.6.0_sr13.0-0.8.1 java-1_6_0-ibm-plugin >= 1.6.0_sr13.0-0.8.1
| Builds SAT Patch Nr: 7482 |
| SUSE Linux Enterprise Server 10 SP4 for x86 | java-1_6_0-ibm >= 1.6.0_sr13.0-0.13.3 java-1_6_0-ibm-alsa >= 1.6.0_sr13.0-0.13.3 java-1_6_0-ibm-devel >= 1.6.0_sr13.0-0.13.3 java-1_6_0-ibm-fonts >= 1.6.0_sr13.0-0.13.3 java-1_6_0-ibm-jdbc >= 1.6.0_sr13.0-0.13.3 java-1_6_0-ibm-plugin >= 1.6.0_sr13.0-0.13.3
| Builds ZYPP Patch Nr: 8495 |
| SUSE Linux Enterprise Server 10 SP4 for IBM POWER | java-1_6_0-ibm >= 1.6.0_sr13.0-0.13.3 java-1_6_0-ibm-64bit >= 1.6.0_sr13.0-0.13.3 java-1_6_0-ibm-devel >= 1.6.0_sr13.0-0.13.3 java-1_6_0-ibm-fonts >= 1.6.0_sr13.0-0.13.3 java-1_6_0-ibm-jdbc >= 1.6.0_sr13.0-0.13.3 java-1_6_0-ibm-plugin >= 1.6.0_sr13.0-0.13.3
| Builds ZYPP Patch Nr: 8495 |
| SUSE Linux Enterprise Server 10 SP4 for IBM zSeries 64bit | java-1_6_0-ibm >= 1.6.0_sr13.0-0.13.3 java-1_6_0-ibm-32bit >= 1.6.0_sr13.0-0.13.3 java-1_6_0-ibm-devel >= 1.6.0_sr13.0-0.13.3 java-1_6_0-ibm-devel-32bit >= 1.6.0_sr13.0-0.13.3 java-1_6_0-ibm-fonts >= 1.6.0_sr13.0-0.13.3 java-1_6_0-ibm-jdbc >= 1.6.0_sr13.0-0.13.3
| Builds ZYPP Patch Nr: 8495 |
| SUSE Linux Enterprise Server 10 SP4 for AMD64 and Intel EM64T | java-1_6_0-ibm >= 1.6.0_sr13.0-0.13.3 java-1_6_0-ibm-32bit >= 1.6.0_sr13.0-0.13.3 java-1_6_0-ibm-alsa-32bit >= 1.6.0_sr13.0-0.13.3 java-1_6_0-ibm-devel >= 1.6.0_sr13.0-0.13.3 java-1_6_0-ibm-devel-32bit >= 1.6.0_sr13.0-0.13.3 java-1_6_0-ibm-fonts >= 1.6.0_sr13.0-0.13.3 java-1_6_0-ibm-jdbc >= 1.6.0_sr13.0-0.13.3 java-1_6_0-ibm-plugin >= 1.6.0_sr13.0-0.13.3 java-1_6_0-ibm-plugin-32bit >= 1.6.0_sr13.0-0.13.3
| Builds ZYPP Patch Nr: 8495 |
| SUSE Linux Enterprise Software Development Kit 11 SP2 | java-1_7_0-ibm-devel >= 1.7.0_sr4.0-0.6.1
| Builds SAT Patch Nr: 7454 |
SUSE Linux Enterprise Server 11 SP2 SUSE Linux Enterprise Server 11 SP2 for VMware | java-1_7_0-ibm >= 1.7.0_sr4.0-0.6.1 java-1_7_0-ibm-alsa >= 1.7.0_sr4.0-0.6.1 java-1_7_0-ibm-jdbc >= 1.7.0_sr4.0-0.6.1 java-1_7_0-ibm-plugin >= 1.7.0_sr4.0-0.6.1
| Builds SAT Patch Nr: 7454 |
SUSE Linux Enterprise Server 11 SP2 SUSE Linux Enterprise Server 11 SP2 for VMware | java-1_7_0-ibm >= 1.7.0_sr4.0-0.6.1 java-1_7_0-ibm-jdbc >= 1.7.0_sr4.0-0.6.1 java-1_7_0-ibm-plugin >= 1.7.0_sr4.0-0.6.1
| Builds SAT Patch Nr: 7454 |
| SUSE Linux Enterprise Server 11 SP2 | java-1_7_0-ibm >= 1.7.0_sr4.0-0.6.1 java-1_7_0-ibm-jdbc >= 1.7.0_sr4.0-0.6.1
| Builds SAT Patch Nr: 7454 |
| SUSE Linux Enterprise Software Development Kit 11 SP2 | java-1_6_0-ibm >= 1.6.0_sr13.0-0.8.1 java-1_6_0-ibm-devel >= 1.6.0_sr13.0-0.8.1 java-1_6_0-ibm-fonts >= 1.6.0_sr13.0-0.8.1
| Builds SAT Patch Nr: 7481 |
| SUSE Linux Enterprise Software Development Kit 11 SP2 | java-1_6_0-ibm-devel >= 1.6.0_sr13.0-0.8.1
| Builds SAT Patch Nr: 7481 |
SUSE Linux Enterprise Server 11 SP2 SUSE Linux Enterprise Server 11 SP2 for VMware | java-1_6_0-ibm >= 1.6.0_sr13.0-0.8.1 java-1_6_0-ibm-alsa >= 1.6.0_sr13.0-0.8.1 java-1_6_0-ibm-fonts >= 1.6.0_sr13.0-0.8.1 java-1_6_0-ibm-jdbc >= 1.6.0_sr13.0-0.8.1 java-1_6_0-ibm-plugin >= 1.6.0_sr13.0-0.8.1
| Builds SAT Patch Nr: 7481 |
SUSE Linux Enterprise Server 11 SP2 SUSE Linux Enterprise Server 11 SP2 for VMware | java-1_6_0-ibm >= 1.6.0_sr13.0-0.8.1 java-1_6_0-ibm-fonts >= 1.6.0_sr13.0-0.8.1 java-1_6_0-ibm-jdbc >= 1.6.0_sr13.0-0.8.1 java-1_6_0-ibm-plugin >= 1.6.0_sr13.0-0.8.1
| Builds SAT Patch Nr: 7481 |
| SUSE Linux Enterprise Server 11 SP2 | java-1_6_0-ibm >= 1.6.0_sr13.0-0.8.1 java-1_6_0-ibm-fonts >= 1.6.0_sr13.0-0.8.1 java-1_6_0-ibm-jdbc >= 1.6.0_sr13.0-0.8.1
| Builds SAT Patch Nr: 7481 |