{"schema_version":"1.7.3","id":"SUSE-SU-2025:02545-1","published":"2025-07-30T06:34:52Z","modified":"2026-02-04T03:21:03.066045Z","related":["CVE-2025-30749","CVE-2025-30754","CVE-2025-30761","CVE-2025-50059"],"upstream":["CVE-2025-30749","CVE-2025-30754","CVE-2025-30761","CVE-2025-50059"],"summary":"Security update for java-1_8_0-openj9","details":"This update for java-1_8_0-openj9 fixes the following issues:\n\nUpdate to OpenJDK 8u462 build 08 with OpenJ9 0.53.0 virtual machine:\n\n- CVE-2025-30749: several scenarios can lead to heap corruption (Oracle CPU 2025-07) (bsc#1246595)\n- CVE-2025-30754: incomplete handshake may lead to weakening TLS protections (Oracle CPU 2025-07) (bsc#1246598)\n- CVE-2025-30761: Improve scripting supports (Oracle CPU 2025-07) (bsc#1246580)\n- CVE-2025-50059: Improve HTTP client header handling (Oracle CPU 2025-07) (bsc#1246575)\n","affected":[{"package":{"name":"java-1_8_0-openj9","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP6","purl":"pkg:rpm/suse/java-1_8_0-openj9&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.0.462-150200.3.57.1"}]}],"ecosystem_specific":{"binaries":[{"java-1_8_0-openj9":"1.8.0.462-150200.3.57.1","java-1_8_0-openj9-accessibility":"1.8.0.462-150200.3.57.1","java-1_8_0-openj9-demo":"1.8.0.462-150200.3.57.1","java-1_8_0-openj9-devel":"1.8.0.462-150200.3.57.1","java-1_8_0-openj9-headless":"1.8.0.462-150200.3.57.1","java-1_8_0-openj9-src":"1.8.0.462-150200.3.57.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:02545-1.json"}},{"package":{"name":"java-1_8_0-openj9","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","purl":"pkg:rpm/suse/java-1_8_0-openj9&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.0.462-150200.3.57.1"}]}],"ecosystem_specific":{"binaries":[{"java-1_8_0-openj9":"1.8.0.462-150200.3.57.1","java-1_8_0-openj9-accessibility":"1.8.0.462-150200.3.57.1","java-1_8_0-openj9-demo":"1.8.0.462-150200.3.57.1","java-1_8_0-openj9-devel":"1.8.0.462-150200.3.57.1","java-1_8_0-openj9-headless":"1.8.0.462-150200.3.57.1","java-1_8_0-openj9-src":"1.8.0.462-150200.3.57.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:02545-1.json"}},{"package":{"name":"java-1_8_0-openj9","ecosystem":"openSUSE:Leap 15.6","purl":"pkg:rpm/opensuse/java-1_8_0-openj9&distro=openSUSE%20Leap%2015.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.0.462-150200.3.57.1"}]}],"ecosystem_specific":{"binaries":[{"java-1_8_0-openj9":"1.8.0.462-150200.3.57.1","java-1_8_0-openj9-accessibility":"1.8.0.462-150200.3.57.1","java-1_8_0-openj9-demo":"1.8.0.462-150200.3.57.1","java-1_8_0-openj9-devel":"1.8.0.462-150200.3.57.1","java-1_8_0-openj9-headless":"1.8.0.462-150200.3.57.1","java-1_8_0-openj9-javadoc":"1.8.0.462-150200.3.57.1","java-1_8_0-openj9-src":"1.8.0.462-150200.3.57.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:02545-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2025/suse-su-202502545-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1246575"},{"type":"REPORT","url":"https://bugzilla.suse.com/1246580"},{"type":"REPORT","url":"https://bugzilla.suse.com/1246595"},{"type":"REPORT","url":"https://bugzilla.suse.com/1246598"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-30749"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-30754"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-30761"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-50059"}]}