🛡️ SUSE-SU-2025:01788-1 — java-1-8-0-ibm (CVE-2025-21587 +3 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for java-1_8_0-ibm

This update for java-1_8_0-ibm fixes the following issues:

Update to Java 8.0 Service Refresh 8 Fix Pack 45.

Security issues fixed:

  • Oracle April 15 2025 CPU (bsc#1242208)
  • CVE-2025-21587: unauthorized access, deletion and modification of critical data via the JSSE component

(bsc#1241274).

  • CVE-2025-30691: unauthorized access to data via the Compiler component (bsc#1241275).
  • CVE-2025-30698: unauthorized access to data and ability to cause a partial DoS via the 2D component (bsc#1241276).
  • IBM Security Update May 2025
  • CVE-2025-4447: stack based buffer overflow in Eclipse OpenJ9 through modification of file that is read when the JVM

starts (bsc#1243429).

Other changes and issues fixed:

  • Security:
  • Avoid memory leak during aes cipher initialization operations

for IBMJCEPlus and IBMJCEPlusProviders provider.

  • Changing the default of the com.ibm.security.spnego.msinterop

property from true to false.

  • Deserializing a com.ibm.crypto.provider.rsaprivatecrtkey object

causes a java.io.invalidobjectexception to be thrown.

  • Failed to read private key from a JKS keystore, specified as

JCEKS keystore.

  • HTTPS channel binding support.
  • Keytool listing PKCS12 keystore issue.
  • On Linux systems, use gcc11.2 to compile IBM PKCS11 library.
  • Support has been added to the IBM Java XMLDSigRI security provider

for the EdDSA (Edwards-curve Digital Signature Algorithm).

  • Updates to XDH Key Agreement, AESGCM Algorithms in IBMJCEPlus

and IBMJCEPlusFIPS providers.

  • Class Libraries:
  • Update timezone information to the latest tzdata2025a.
  • Java Virtual Machine:
  • A SIGSEGV/GPF event received while processing verifyerror.
  • Crash while resolving MethodHandleNatives.
  • NoSuchMethodException or NoClassDefFoundError when loading classes.
  • JIT Compiler:
  • Assert in the JIT Compiler, badILOp.
  • Reduced MD5 performance.

Affected software

SUSE-SU-2025:01788-1 is recorded against 1 package.

  • java-1-8-0-ibm (fixed in 1.8.0_sr8.45-150000.3.101.1)

Timeline and source

Published on 31 May 2025 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-05-31
Updated 2026-08-20
Modified 2026-03-23
Fix URL N/A

Affected Packages

Software From version Fixed in
java-1-8-0-ibm 1.8.0_sr8.45-150000.3.101.1

Free Vulnerability Check

Is your site affected by SUSE-SU-2025:01788-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2025:01788-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2025