RHSA-2020:0856: Important: java-1.8.0-ibm security update
IBM Java SE version 8 includes the IBM Java Runtime Environment and the IBM Java Software Development Kit.This update upgrades IBM Java SE 8 to version 8 SR6-FP5.Security Fix(es): OpenJDK: Serialization filter changes via jdk.serialFilter property modification (Serialization, 8231422) (CVE-2020-2604) OpenJDK: Incorrect isBuiltinStreamHandler check causing URL normalization issues (Networking, 8228548) (CVE-2020-2593) OpenJDK: Incorrect exception processing during deserialization in BeanContextSupport (Serialization, 8224909) (CVE-2020-2583) OpenJDK: Incomplete enforcement of maxDatagramSockets limit in DatagramChannelImpl (Networking, 8231795) (CVE-2020-2659) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-ibm-1.8.0.6.5-1jpp.1.el6_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-ibm-devel-1.8.0.6.5-1jpp.1.el6_10
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:0856?
RHSA-2020:0856 has a critical severity rating due to the potential exploitation of the vulnerability in IBM Java SE 8.
How do I fix RHSA-2020:0856?
To fix RHSA-2020:0856, upgrade IBM Java SE to version 8 SR6-FP5 or later.
Which software is affected by RHSA-2020:0856?
RHSA-2020:0856 affects specific versions of IBM Java SE 8, including 1.8.0-ibm and 1.8.0-ibm-devel up to 1.8.0-ibm-1.8.0.6.5-1jpp.1.el6_10.
What are the security fixes included in RHSA-2020:0856?
RHSA-2020:0856 includes security fixes for serialization filter changes via jdk.serialFilter property modification.
When was RHSA-2020:0856 released?
RHSA-2020:0856 was released in 2020 as part of a regular security update for IBM Java SE.