Environment
Novell Open Enterprise Server 11 (OES 11) Linux Support Pack 2
Novell GroupWise
Novell GroupWise
Situation
Oracle released a list of patches "Oracle Critical Patch Update Advisory - July 2015". The purpose of this TID is to discuss the CVE numbers listed relevant to Novell products.
Resolution
Novell is currently analyzing the CVE numbers provided by Oracle to ensure that all relevant Java updates are applied to products that use the Oracle Java stack.
Additional Information
Additional information may be found here:
CVE-2015-2601 (CVSS 5.0) JCE
CVE-2015-2659 (CVSS 5.0) Security
CVE-2015-4749 (CVSS 4.3) JNDI
CVE-2015-4000 (CVSS 4.0) JSSE
CVE-2015-2808 (CVSS 4.0) JSSE
CVE-2015-2625 (CVSS 2.6) JSSE
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
Summary of CVE numbers and analysis:
CVE-2015-4748 (CVSS 7.6) Security
Very difficult to exploit vulnerability allows successful unauthenticated network attacks via OCSP. Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.
CVE-2015-2601 (CVSS 5.0) JCE
Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized read access to a subset of Java SE, JRockit, Java SE Embedded accessible data.
CVE-2015-2659 (CVSS 5.0) Security
Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded.
CVE-2015-4749 (CVSS 4.3) JNDI
Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, JRockit, Java SE Embedded.
CVE-2015-4000 (CVSS 4.0) JSSE
Very difficult to exploit vulnerability allows successful unauthenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some Java SE, JRockit, Java SE Embedded accessible data as well as read access to a subset of Java SE, JRockit, Java SE Embedded accessible data.
CVE-2015-2808 (CVSS 4.0) JSSE
Very difficult to exploit vulnerability allows successful unauthenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some Java SE, JRockit, Java SE Embedded accessible data as well as read access to a subset of Java SE, JRockit, Java SE Embedded accessible data.
CVE-2015-2625 (CVSS 2.6) JSSE
Very difficult to exploit vulnerability allows successful unauthenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Java SE, JRockit, Java SE Embedded accessible data.