← Search the atlas
SUSE-SU-2021:0512-1
Not scored
Security update for java-1_7_1-ibm
This update for java-1_7_1-ibm fixes the following issues:
- Update to Java 7.1 Service Refresh 4 Fix Pack 80
[bsc#1182186, bsc#1181239, CVE-2020-27221, CVE-2020-14803]
* CVE-2020-27221: Potential for a stack-based buffer overflow
when the virtual machine or JNI natives are converting from
UTF-8 characters to platform encoding.
* CVE-2020-14803: Unauthenticated attacker with network access
via multiple protocols allows to compromise Java SE.
Exploit probability
Not scored
Published
February 18, 2021
Required by
Not available
Last source change
February 4, 2026
02 / AFFECTED SOFTWARE
Affected packages
SUSE:HPE Helion OpenStack 8
java-1_7_1-ibm
SUSE:Linux Enterprise Server 12 SP2-BCL
java-1_7_1-ibm
SUSE:Linux Enterprise Server 12 SP2-LTSS
java-1_7_1-ibm
SUSE:Linux Enterprise Server 12 SP3-BCL
java-1_7_1-ibm
SUSE:Linux Enterprise Server 12 SP3-LTSS
java-1_7_1-ibm
SUSE:Linux Enterprise Server 12 SP4-LTSS
java-1_7_1-ibm
SUSE:Linux Enterprise Server 12 SP5
java-1_7_1-ibm
SUSE:Linux Enterprise Server for SAP Applications 12 SP2
java-1_7_1-ibm
SUSE:Linux Enterprise Server for SAP Applications 12 SP3
java-1_7_1-ibm
SUSE:Linux Enterprise Server for SAP Applications 12 SP4
java-1_7_1-ibm
SUSE:Linux Enterprise Server for SAP Applications 12 SP5
java-1_7_1-ibm
SUSE:Linux Enterprise Software Development Kit 12 SP5
java-1_7_1-ibm
SUSE:OpenStack Cloud 7
java-1_7_1-ibm
SUSE:OpenStack Cloud 8
java-1_7_1-ibm
SUSE:OpenStack Cloud 9
java-1_7_1-ibm
SUSE:OpenStack Cloud Crowbar 8
java-1_7_1-ibm
SUSE:OpenStack Cloud Crowbar 9
java-1_7_1-ibm
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
SUSE-SU-2021:0512-1
This update for java-1_7_1-ibm fixes the following issues:
- Update to Java 7.1 Service Refresh 4 Fix Pack 80
[bsc#1182186, bsc#1181239, CVE-2020-27221, CVE-2020-14803]
* CVE-2020-27221: Potential for a stack-based buffer overflow
when the virtual machine or JNI natives are converting from
UTF-8 characters to platform encoding.
* CVE-2020-14803: Unauthenticated attacker with network access
via multiple protocols allows to compromise Java SE.
View original source ↗
05 / REFERENCES
Further evidence