Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java…: 45 records in one advisory
45 records announced together, published between 2011-06-14 and 2013-06-18, every one of them citing the same advisory.
The advisory
Every record in this batch cites http://rhn.redhat.com/errata/RHSA-2013-1455.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.
What the records offer
No record in this batch publishes a fixed version in held sources.
1 record is listed by CISA with a required action, which carries a federal remediation deadline on its own page.
22 of 45 records name something of its own. For the other 23, held sources say the same thing about each.
What this page does not cover
This batch is 45 of the 156 records that cite the same advisory. The other 111 are different findings announced alongside it.
None of those 111 is grouped with any other. Each one has its own record page and nothing else.
The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.
What this batch was researched, not held
Red Hat refreshing the IBM Java buried inside Satellite, two years of fixes at once
Red Hat issued this advisory on 23 October 2013, and it updates exactly one thing: the java-1.6.0-ibm packages shipped as part of Red Hat Network Satellite Server 5.4. Red Hat describes the change as moving those packages to IBM Java SE 6 SR14, and lists in one paragraph the identifiers that move addresses in those packages, dated from 2011 to 2013, with no description beyond a line saying several flaws were fixed in the IBM Java 2 Runtime Environment. Red Hat rated the whole advisory Low and said plainly why: in a typical operating environment, these are of low security risk as the runtime is not used on untrusted applets. Most of the identifiers begin life in Oracle's quarterly Java Critical Patch Updates, which publish a scored table of affected components instead of a description of each flaw, which is why the records read almost identically.
Each identifier here is a separate defect in a Java runtime, found by different people at different times over two years. Red Hat gathered them into one advisory because one set of packages carries them all, not because they are related to each other. Red Hat's Low rating describes this product, where the runtime never handles untrusted applets, and says nothing about how serious any of these flaws are anywhere else. Three identifiers listed in the advisory are in the CISA catalogue of vulnerabilities known to have been exploited: CVE-2011-3544, CVE-2012-0507 and CVE-2013-2465.
The advisory maps no identifier to a component or to a specific IBM runtime version, so it cannot tell you which ones mattered on your server. There is also a counting gap worth stating: our index holds 156 records naming this advisory, 45 of them in this group, and two automated reads of the live errata page returned different totals for its own list. Nobody can settle from the page alone how many identifiers the advisory claims.
Written from access.redhat.com, oracle.com, cisa.gov. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.
Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.
45 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.