Oval Definition:oval:org.opensuse.security:def:20212432
Revision Date:2022-09-02Version:1
Title:CVE-2021-2432
Description:

Vulnerability in the Java SE product of Oracle Java SE (component: JNDI). The supported version that is affected is Java SE: 7u301. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2021-2432
SUSE CVE-2021-2432
SUSE-SU-2021:3007-1
SUSE-SU-2022:0166-1
SUSE-SU-2022:14875-1
SUSE-SU-2022:14876-1
Platform(s):SUSE Linux Enterprise High Performance Computing 12 SP5
SUSE Linux Enterprise Server 11 SP3-TERADATA
SUSE Linux Enterprise Server 11 SP4-LTSS
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4-ESPOS
SUSE Linux Enterprise Server 12 SP4-LTSS
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Server for SAP Applications 12 SP5
SUSE Linux Enterprise Software Development Kit 12 SP5
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud 9
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud Crowbar 9
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • java-1_7_0-openjdk-1.7.0.311-43.50.2 is installed
  • OR java-1_7_0-openjdk-demo-1.7.0.311-43.50.2 is installed
  • OR java-1_7_0-openjdk-devel-1.7.0.311-43.50.2 is installed
  • OR java-1_7_0-openjdk-headless-1.7.0.311-43.50.2 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND
  • java-1_7_0-openjdk-1.7.0.311-43.50.2 is installed
  • OR java-1_7_0-openjdk-demo-1.7.0.311-43.50.2 is installed
  • OR java-1_7_0-openjdk-devel-1.7.0.311-43.50.2 is installed
  • OR java-1_7_0-openjdk-headless-1.7.0.311-43.50.2 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
  • AND
  • java-1_7_0-openjdk-1.7.0.311-43.50.2 is installed
  • OR java-1_7_0-openjdk-demo-1.7.0.311-43.50.2 is installed
  • OR java-1_7_0-openjdk-devel-1.7.0.311-43.50.2 is installed
  • OR java-1_7_0-openjdk-headless-1.7.0.311-43.50.2 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 11 SP3-TERADATA is installed
  • AND
  • java-1_7_0-ibm-1.7.0_sr11.0-65.63.1 is installed
  • OR java-1_7_0-ibm-alsa-1.7.0_sr11.0-65.63.1 is installed
  • OR java-1_7_0-ibm-jdbc-1.7.0_sr11.0-65.63.1 is installed
  • OR java-1_7_0-ibm-plugin-1.7.0_sr11.0-65.63.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP4-LTSS is installed
  • AND
  • java-1_7_1-ibm-1.7.1_sr5.0-26.68.1 is installed
  • OR java-1_7_1-ibm-alsa-1.7.1_sr5.0-26.68.1 is installed
  • OR java-1_7_1-ibm-devel-1.7.1_sr5.0-26.68.1 is installed
  • OR java-1_7_1-ibm-jdbc-1.7.1_sr5.0-26.68.1 is installed
  • OR java-1_7_1-ibm-plugin-1.7.1_sr5.0-26.68.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • java-1_7_1-ibm-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-alsa-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-devel-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-jdbc-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-plugin-1.7.1_sr5.0-38.65.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND
  • java-1_7_0-openjdk-1.7.0.311-43.50.2 is installed
  • OR java-1_7_0-openjdk-demo-1.7.0.311-43.50.2 is installed
  • OR java-1_7_0-openjdk-devel-1.7.0.311-43.50.2 is installed
  • OR java-1_7_0-openjdk-headless-1.7.0.311-43.50.2 is installed
  • OR java-1_7_1-ibm-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-alsa-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-devel-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-jdbc-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-plugin-1.7.1_sr5.0-38.65.1 is installed
  • OR Package Information
  • SUSE OpenStack Cloud 8 is installed
  • OR SUSE OpenStack Cloud Crowbar 8 is installed
  • AND
  • java-1_7_1-ibm-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-alsa-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-devel-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-jdbc-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-plugin-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_0-openjdk is affected
  • OR java-1_7_0-openjdk-demo is affected
  • OR java-1_7_0-openjdk-devel is affected
  • OR java-1_7_0-openjdk-headless is affected
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • OR SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND
  • java-1_7_1-ibm-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-alsa-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-devel-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-jdbc-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-plugin-1.7.1_sr5.0-38.65.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND
  • java-1_7_1-ibm-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-alsa-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-devel-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-jdbc-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-plugin-1.7.1_sr5.0-38.65.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 12 SP4-ESPOS is installed
  • OR SUSE OpenStack Cloud 9 is installed
  • OR SUSE OpenStack Cloud Crowbar 9 is installed
  • AND
  • java-1_7_1-ibm-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-alsa-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-devel-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-jdbc-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-plugin-1.7.1_sr5.0-38.65.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP4-LTSS is installed
  • AND
  • java-1_7_1-ibm-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-alsa-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-devel-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-jdbc-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-plugin-1.7.1_sr5.0-38.65.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
  • OR SUSE Linux Enterprise Software Development Kit 12 SP5 is installed
  • AND java-1_7_1-ibm-devel-1.7.1_sr5.0-38.65.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
  • AND
  • java-1_7_0-openjdk-1.7.0.311-43.50.2 is installed
  • OR java-1_7_0-openjdk-demo-1.7.0.311-43.50.2 is installed
  • OR java-1_7_0-openjdk-devel-1.7.0.311-43.50.2 is installed
  • OR java-1_7_0-openjdk-headless-1.7.0.311-43.50.2 is installed
  • OR java-1_7_1-ibm-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-alsa-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-devel-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-jdbc-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-plugin-1.7.1_sr5.0-38.65.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Performance Computing 12 SP5 is installed
  • AND java-1_7_1-ibm is affected
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
  • OR SUSE Linux Enterprise Software Development Kit 12 SP5 is installed
  • AND java-1_7_1-ibm-devel-1.7.1_sr5.0-38.65.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
  • AND
  • java-1_7_0-openjdk-1.7.0.311-43.50.2 is installed
  • OR java-1_7_0-openjdk-demo-1.7.0.311-43.50.2 is installed
  • OR java-1_7_0-openjdk-devel-1.7.0.311-43.50.2 is installed
  • OR java-1_7_0-openjdk-headless-1.7.0.311-43.50.2 is installed
  • OR java-1_7_1-ibm-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-alsa-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-devel-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-jdbc-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-plugin-1.7.1_sr5.0-38.65.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
  • AND
  • java-1_7_1-ibm-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-alsa-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-devel-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-jdbc-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-plugin-1.7.1_sr5.0-38.65.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP4-ESPOS is installed
  • AND
  • java-1_7_1-ibm-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-alsa-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-devel-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-jdbc-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-plugin-1.7.1_sr5.0-38.65.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP4-LTSS is installed
  • AND
  • java-1_7_1-ibm-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-alsa-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-devel-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-jdbc-1.7.1_sr5.0-38.65.1 is installed
  • OR java-1_7_1-ibm-plugin-1.7.1_sr5.0-38.65.1 is installed
  • BACK