<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for java-1_7_0-ibm</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2016:1378-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2016-05-20T21:06:13Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2016-05-20T21:06:13Z</InitialReleaseDate>
    <CurrentReleaseDate>2016-05-20T21:06:13Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for java-1_7_0-ibm</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">
This IBM Java 1.7.0 SR9 FP40 release fixes the following issues:

Security issues fixed:
- CVE-2016-0264: buffer overflow vulnerability in the IBM JVM (bsc#977648)
- CVE-2016-0363: insecure use of invoke method in CORBA component, incorrect CVE-2013-3009 fix (bsc#977650)
- CVE-2016-0376: insecure deserialization in CORBA, incorrect CVE-2013-5456 fix (bsc#977646)
- The following CVEs got also fixed during this update. (bsc#979252)
  CVE-2016-3443, CVE-2016-0687, CVE-2016-0686, CVE-2016-3427, CVE-2016-3449, CVE-2016-3422, CVE-2016-3426
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">sleclo50sp3-java-1_7_0-ibm-12571,sleman21-java-1_7_0-ibm-12571,slemap21-java-1_7_0-ibm-12571,slessp2-java-1_7_0-ibm-12571,slessp3-java-1_7_0-ibm-12571</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20161378-1/</URL>
      <Description>Link for SUSE-SU-2016:1378-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00058.html</URL>
      <Description>E-Mail link for SUSE-SU-2016:1378-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/977646</URL>
      <Description>SUSE Bug 977646</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/977648</URL>
      <Description>SUSE Bug 977648</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/977650</URL>
      <Description>SUSE Bug 977650</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/979252</URL>
      <Description>SUSE Bug 979252</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-0264/</URL>
      <Description>SUSE CVE CVE-2016-0264 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-0363/</URL>
      <Description>SUSE CVE CVE-2016-0363 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-0376/</URL>
      <Description>SUSE CVE CVE-2016-0376 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-0686/</URL>
      <Description>SUSE CVE CVE-2016-0686 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-0687/</URL>
      <Description>SUSE CVE CVE-2016-0687 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-3422/</URL>
      <Description>SUSE CVE CVE-2016-3422 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-3426/</URL>
      <Description>SUSE CVE CVE-2016-3426 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-3427/</URL>
      <Description>SUSE CVE CVE-2016-3427 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-3443/</URL>
      <Description>SUSE CVE CVE-2016-3443 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-3449/</URL>
      <Description>SUSE CVE CVE-2016-3449 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 11 SP2-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS" CPE="cpe:/o:suse:suse_sles_ltss:11:sp2">SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 11 SP3-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 11 SP3-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-LTSS" CPE="cpe:/o:suse:suse_sles_ltss:11:sp3">SUSE Linux Enterprise Server 11 SP3-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 11 SP3-TERADATA">
        <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA" CPE="cpe:/o:suse:sles:11:sp3:teradata">SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager 2.1">
      <Branch Type="Product Name" Name="SUSE Manager 2.1">
        <FullProductName ProductID="SUSE Manager 2.1" CPE="cpe:/o:suse:suse-manager-server:2.1">SUSE Manager 2.1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Proxy 2.1">
      <Branch Type="Product Name" Name="SUSE Manager Proxy 2.1">
        <FullProductName ProductID="SUSE Manager Proxy 2.1">SUSE Manager Proxy 2.1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE OpenStack Cloud 5">
      <Branch Type="Product Name" Name="SUSE OpenStack Cloud 5">
        <FullProductName ProductID="SUSE OpenStack Cloud 5" CPE="cpe:/o:suse:cloud:5">SUSE OpenStack Cloud 5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="java-1_7_0-ibm-1.7.0_sr9.40-52.1">
      <FullProductName ProductID="java-1_7_0-ibm-1.7.0_sr9.40-52.1">java-1_7_0-ibm-1.7.0_sr9.40-52.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1">
      <FullProductName ProductID="java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1">java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1">
      <FullProductName ProductID="java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1">java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1">
      <FullProductName ProductID="java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1">java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="java-1_7_0-ibm-devel-1.7.0_sr9.40-52.1">
      <FullProductName ProductID="java-1_7_0-ibm-devel-1.7.0_sr9.40-52.1">java-1_7_0-ibm-devel-1.7.0_sr9.40-52.1</FullProductName>
    </Branch>
    <Relationship ProductReference="java-1_7_0-ibm-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-1.7.0_sr9.40-52.1">java-1_7_0-ibm-1.7.0_sr9.40-52.1 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1">java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1_7_0-ibm-devel-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-devel-1.7.0_sr9.40-52.1">java-1_7_0-ibm-devel-1.7.0_sr9.40-52.1 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1">java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1">java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1 as a component of SUSE Linux Enterprise Server 11 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1_7_0-ibm-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-1.7.0_sr9.40-52.1">java-1_7_0-ibm-1.7.0_sr9.40-52.1 as a component of SUSE Linux Enterprise Server 11 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1">java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1 as a component of SUSE Linux Enterprise Server 11 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1">java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1 as a component of SUSE Linux Enterprise Server 11 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1">java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1 as a component of SUSE Linux Enterprise Server 11 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1_7_0-ibm-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-1.7.0_sr9.40-52.1">java-1_7_0-ibm-1.7.0_sr9.40-52.1 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1">java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1">java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1">java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1_7_0-ibm-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:java-1_7_0-ibm-1.7.0_sr9.40-52.1">java-1_7_0-ibm-1.7.0_sr9.40-52.1 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1">java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1">java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1">java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1_7_0-ibm-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy 2.1">
      <FullProductName ProductID="SUSE Manager Proxy 2.1:java-1_7_0-ibm-1.7.0_sr9.40-52.1">java-1_7_0-ibm-1.7.0_sr9.40-52.1 as a component of SUSE Manager Proxy 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy 2.1">
      <FullProductName ProductID="SUSE Manager Proxy 2.1:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1">java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1 as a component of SUSE Manager Proxy 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy 2.1">
      <FullProductName ProductID="SUSE Manager Proxy 2.1:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1">java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1 as a component of SUSE Manager Proxy 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy 2.1">
      <FullProductName ProductID="SUSE Manager Proxy 2.1:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1">java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1 as a component of SUSE Manager Proxy 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1_7_0-ibm-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 5">
      <FullProductName ProductID="SUSE OpenStack Cloud 5:java-1_7_0-ibm-1.7.0_sr9.40-52.1">java-1_7_0-ibm-1.7.0_sr9.40-52.1 as a component of SUSE OpenStack Cloud 5</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 5">
      <FullProductName ProductID="SUSE OpenStack Cloud 5:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1">java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1 as a component of SUSE OpenStack Cloud 5</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 5">
      <FullProductName ProductID="SUSE OpenStack Cloud 5:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1">java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1 as a component of SUSE OpenStack Cloud 5</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 5">
      <FullProductName ProductID="SUSE OpenStack Cloud 5:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1">java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1 as a component of SUSE OpenStack Cloud 5</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) allows remote attackers to execute arbitrary code via unspecified vectors.</Note>
    </Notes>
    <CVE>CVE-2016-0264</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-devel-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.1</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20161378-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-0264.html</URL>
        <Description>CVE-2016-0264</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/977648</URL>
        <Description>SUSE Bug 977648</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/979252</URL>
        <Description>SUSE Bug 979252</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController doPrivileged block, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to a Proxy object instance implementing the java.lang.reflect.InvocationHandler interface.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3009.</Note>
    </Notes>
    <CVE>CVE-2016-0363</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-devel-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.6</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20161378-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-0363.html</URL>
        <Description>CVE-2016-0363</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/977650</URL>
        <Description>SUSE Bug 977650</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/979252</URL>
        <Description>SUSE Bug 979252</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not properly deserialize classes in an AccessController doPrivileged block, which allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code as demonstrated by the readValue method of the com.ibm.rmi.io.ValueHandlerPool.ValueHandlerSingleton class, which implements the javax.rmi.CORBA.ValueHandler interface.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-5456.</Note>
    </Notes>
    <CVE>CVE-2016-0376</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-devel-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.6</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20161378-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-0376.html</URL>
        <Description>CVE-2016-0376</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/977646</URL>
        <Description>SUSE Bug 977646</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/977650</URL>
        <Description>SUSE Bug 977650</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/979252</URL>
        <Description>SUSE Bug 979252</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/981057</URL>
        <Description>SUSE Bug 981057</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/981060</URL>
        <Description>SUSE Bug 981060</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/981087</URL>
        <Description>SUSE Bug 981087</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Serialization.</Note>
    </Notes>
    <CVE>CVE-2016-0686</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-devel-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>10</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20161378-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-0686.html</URL>
        <Description>CVE-2016-0686</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/976340</URL>
        <Description>SUSE Bug 976340</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/979252</URL>
        <Description>SUSE Bug 979252</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to the Hotspot sub-component.</Note>
    </Notes>
    <CVE>CVE-2016-0687</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-devel-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>10</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20161378-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-0687.html</URL>
        <Description>CVE-2016-0687</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/976340</URL>
        <Description>SUSE Bug 976340</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/979252</URL>
        <Description>SUSE Bug 979252</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect availability via vectors related to 2D.</Note>
    </Notes>
    <CVE>CVE-2016-3422</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-devel-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20161378-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-3422.html</URL>
        <Description>CVE-2016-3422</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/976340</URL>
        <Description>SUSE Bug 976340</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/979252</URL>
        <Description>SUSE Bug 979252</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality via vectors related to JCE.</Note>
    </Notes>
    <CVE>CVE-2016-3426</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-devel-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20161378-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-3426.html</URL>
        <Description>CVE-2016-3426</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/976340</URL>
        <Description>SUSE Bug 976340</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/979252</URL>
        <Description>SUSE Bug 979252</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.</Note>
    </Notes>
    <CVE>CVE-2016-3427</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-devel-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>10</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20161378-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-3427.html</URL>
        <Description>CVE-2016-3427</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1011805</URL>
        <Description>SUSE Bug 1011805</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/976340</URL>
        <Description>SUSE Bug 976340</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/979252</URL>
        <Description>SUSE Bug 979252</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to 2D.  NOTE: the previous information is from the April 2016 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to obtain sensitive information via crafted font data, which triggers an out-of-bounds read.</Note>
    </Notes>
    <CVE>CVE-2016-3443</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-devel-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>10</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20161378-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-3443.html</URL>
        <Description>CVE-2016-3443</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/976340</URL>
        <Description>SUSE Bug 976340</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/979252</URL>
        <Description>SUSE Bug 979252</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Deployment.</Note>
    </Notes>
    <CVE>CVE-2016-3449</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-devel-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP2-LTSS:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-LTSS:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager 2.1:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE Manager Proxy 2.1:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-alsa-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-jdbc-1.7.0_sr9.40-52.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 5:java-1_7_0-ibm-plugin-1.7.0_sr9.40-52.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.6</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20161378-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-3449.html</URL>
        <Description>CVE-2016-3449</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/976340</URL>
        <Description>SUSE Bug 976340</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/979252</URL>
        <Description>SUSE Bug 979252</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
