Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE Vulnerability Reported on IBM Java 1.8 Version #101

Open
AnandPalani92 opened this issue Nov 5, 2020 · 8 comments
Open

CVE Vulnerability Reported on IBM Java 1.8 Version #101

AnandPalani92 opened this issue Nov 5, 2020 · 8 comments

Comments

@AnandPalani92
Copy link

Hello Team,

We are noticed below CVE vulnerability on IBM-Alpine-Java8 version, We are using following version details.

java version "1.8.0_261" Java(TM) SE Runtime Environment (build 8.0.6.16 - pxa6480sr6fp16-20200902_01(SR6 FP16)) IBM J9 VM (build 2.9, JRE 1.8.0 Linux amd64-64-Bit Compressed References 20200901_454898 (JIT enabled, AOT enabled) OpenJ9 - 2799ddf OMR - b348d97 IBM - 5371022) JCL - 20200831_01 based on Oracle jdk8u261-b13

Kindly take a look and update the docker image. CVE vulnerability information mentioned on below for your reference.
https://www.ibm.com/support/pages/apar/IJ28908
https://www.ibm.com/support/pages/apar/IJ28903
https://www.ibm.com/support/pages/apar/IJ28905

Regards,
Anand Palani

@pshipton
Copy link
Member

pshipton commented Nov 5, 2020

The CVEs are fixed in the next Java releases, which were delayed. Java 7.x (FP75) is due out next week, and Java 8 (FP20) is due out Nov 17 although it will take some extra time for the docker images to get updated.

@AnandPalani92
Copy link
Author

@pshipton Is the CVE'S are fixed? We are not notified through this ticket.
Could you please check and let me know the CVE issues are fixed ?
Regards,
Anand Palani

@pshipton
Copy link
Member

The Java 7.x releases are available since last week. The Java 8 release is delayed again, there is no firm date, not before Dec 9.

@AnandPalani92
Copy link
Author

@pshipton Thanks for the update

@AnandPalani92
Copy link
Author

@pshipton Are we released the Java 8 to fix CVE issues ? I still see the CVE issues on the alpine-java-ibm images

@pshipton
Copy link
Member

The Java 8 fp20 update (8.0.6.20) has been released, https://www.ibm.com/support/pages/java-sdk-downloads-version-80
It looks like docker has been updated to use it 4 days ago.

I see this APAR was re-targeted for 8.0.6.25, the early February release. The others listed in the description are fixed in fp20.
https://www.ibm.com/support/pages/apar/IJ28903

@ramesh-k-repo
Copy link

The Java 8 fp20 update (8.0.6.20) has been released, https://www.ibm.com/support/pages/java-sdk-downloads-version-80
It looks like docker has been updated to use it 4 days ago.

I see this APAR was re-targeted for 8.0.6.25, the early February release. The others listed in the description are fixed in fp20.
https://www.ibm.com/support/pages/apar/IJ28903

@pshipton
I dont see FP25 release yet. Any specific dates known for FP25 release?

@pshipton
Copy link
Member

pshipton commented Feb 4, 2021

Any specific dates known for FP25 release?

It's expected around Feb 11, with the docker updates to follow.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants