vciy

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java…: 45 records in one advisory

45 records announced together, published between 2011-06-14 and 2013-06-18, every one of them citing the same advisory.

The advisory

Every record in this batch cites http://rhn.redhat.com/errata/RHSA-2013-1455.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

No record in this batch publishes a fixed version in held sources.

1 record is listed by CISA with a required action, which carries a federal remediation deadline on its own page.

22 of 45 records name something of its own. For the other 23, held sources say the same thing about each.

What this page does not cover

This batch is 45 of the 156 records that cite the same advisory. The other 111 are different findings announced alongside it.

None of those 111 is grouped with any other. Each one has its own record page and nothing else.

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

What this batch was researched, not held

Red Hat refreshing the IBM Java buried inside Satellite, two years of fixes at once

Red Hat issued this advisory on 23 October 2013, and it updates exactly one thing: the java-1.6.0-ibm packages shipped as part of Red Hat Network Satellite Server 5.4. Red Hat describes the change as moving those packages to IBM Java SE 6 SR14, and lists in one paragraph the identifiers that move addresses in those packages, dated from 2011 to 2013, with no description beyond a line saying several flaws were fixed in the IBM Java 2 Runtime Environment. Red Hat rated the whole advisory Low and said plainly why: in a typical operating environment, these are of low security risk as the runtime is not used on untrusted applets. Most of the identifiers begin life in Oracle's quarterly Java Critical Patch Updates, which publish a scored table of affected components instead of a description of each flaw, which is why the records read almost identically.

Each identifier here is a separate defect in a Java runtime, found by different people at different times over two years. Red Hat gathered them into one advisory because one set of packages carries them all, not because they are related to each other. Red Hat's Low rating describes this product, where the runtime never handles untrusted applets, and says nothing about how serious any of these flaws are anywhere else. Three identifiers listed in the advisory are in the CISA catalogue of vulnerabilities known to have been exploited: CVE-2011-3544, CVE-2012-0507 and CVE-2013-2465.

2013-10-23Red Hat issues this advisory, rating it Low, updating the IBM Java packages in Satellite Server 5.4 to IBM Java SE 6 SR14
2022-03-03CISA adds CVE-2011-3544 and CVE-2012-0507, both listed in this advisory, to the catalogue of vulnerabilities known to have been exploited
2022-03-28CISA adds a third identifier from this advisory, CVE-2013-2465, to the same catalogue

The advisory maps no identifier to a component or to a specific IBM runtime version, so it cannot tell you which ones mattered on your server. There is also a counting gap worth stating: our index holds 156 records naming this advisory, 45 of them in this group, and two automated reads of the live errata page returned different totals for its own list. Nobody can settle from the page alone how many identifiers the advisory claims.

Written from access.redhat.com, oracle.com, cisa.gov. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2011-0802cve-2011-0814
CVE-2011-0814cve-2011-0802
CVE-2011-0863no title held
CVE-2011-0867networking
CVE-2011-0873no title held
CVE-2012-0498no title held
CVE-2012-0499no title held
CVE-2012-0500no title held
CVE-2012-0507concurrency was obtained
CVE-2012-1531no title held
CVE-2012-1532no title held
CVE-2012-1533cve-2012-3159
CVE-2012-1541no title held
CVE-2012-1682beans cve-2012-3136 claims downstream
CVE-2012-1721cve-2012-1722
CVE-2012-1722cve-2012-1721
CVE-2012-3143cve-2012-5089
CVE-2012-3159cve-2012-1533
CVE-2012-3213scripting
CVE-2012-3342no title held
CVE-2012-5079libraries cve-2012-5073
CVE-2012-5083no title held
CVE-2013-0351no title held
CVE-2013-0409no title held
CVE-2013-0419no title held
CVE-2013-0423no title held
CVE-2013-0438no title held
CVE-2013-0446no title held
CVE-2013-1473no title held
CVE-2013-1481no title held
CVE-2013-1540cve-2013-2433
CVE-2013-2394cve-2013-2432
CVE-2013-2418local users
CVE-2013-2432cve-2013-2394
CVE-2013-2433cve-2013-1540
CVE-2013-2435cve-2013-2440
CVE-2013-2437no title held
CVE-2013-2440cve-2013-2435
CVE-2013-2442no title held
CVE-2013-2464cve-2013-2463 cve-2013-2465 cve-2013-2469 cve-2013-2470
CVE-2013-2466no title held
CVE-2013-2468no title held
CVE-2013-3743no title held

45 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.