← Search the atlas
SUSE-SU-2025:3997-1
Not scored
Security update for java-17-openjdk
This update for java-17-openjdk fixes the following issues:
Upgrade to upstream tag jdk-17.0.17+10 (October 2025 CPU):
- CVE-2025-53057: Fixed unauthenticated attacker can achieve unauthorized creation, deletion or modification access to critical data (bsc#1252414).
- CVE-2025-53066: Fixed unauthenticated attacker can achive unauthorized access to critical data or complete access (bsc#1252417).
Other bug fixes:
- Do not embed rebuild counter (bsc#1246806)
Exploit probability
Not scored
Published
November 7, 2025
Required by
Not available
Last source change
February 4, 2026
02 / AFFECTED SOFTWARE
Affected packages
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
java-17-openjdk
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
java-17-openjdk
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
java-17-openjdk
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
java-17-openjdk
SUSE:Linux Enterprise Module for Basesystem 15 SP6
java-17-openjdk
SUSE:Linux Enterprise Module for Legacy 15 SP6
java-17-openjdk
SUSE:Linux Enterprise Module for Legacy 15 SP7
java-17-openjdk
SUSE:Linux Enterprise Server 15 SP4-LTSS
java-17-openjdk
SUSE:Linux Enterprise Server 15 SP5-LTSS
java-17-openjdk
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
java-17-openjdk
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
java-17-openjdk
SUSE:Manager Proxy LTS 4.3
java-17-openjdk
SUSE:Manager Server LTS 4.3
java-17-openjdk
openSUSE:Leap 15.6
java-17-openjdk
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
SUSE-SU-2025:3997-1
This update for java-17-openjdk fixes the following issues:
Upgrade to upstream tag jdk-17.0.17+10 (October 2025 CPU):
- CVE-2025-53057: Fixed unauthenticated attacker can achieve unauthorized creation, deletion or modification access to critical data (bsc#1252414).
- CVE-2025-53066: Fixed unauthenticated attacker can achive unauthorized access to critical data or complete access (bsc#1252417).
Other bug fixes:
- Do not embed rebuild counter (bsc#1246806)
View original source ↗
05 / REFERENCES
Further evidence