<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Java  Multiple Vulnerabilities in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/java-multiple-vulnerabilities/m-p/4343312#M734932</link>
    <description>Hello VK2COT,&lt;BR /&gt;&lt;BR /&gt;Thank for your reply.&lt;BR /&gt;&lt;BR /&gt;Sorry for refering wrong ID.&lt;BR /&gt;&lt;BR /&gt;The vulnerabilities I am checking is VUPEN/ADV-2008-3339&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.vupen.com/english/advisories/2008/3339" target="_blank"&gt;http://www.vupen.com/english/advisories/2008/3339&lt;/A&gt;&lt;BR /&gt;</description>
    <pubDate>Fri, 23 Jan 2009 06:08:18 GMT</pubDate>
    <dc:creator>godchild_ii</dc:creator>
    <dc:date>2009-01-23T06:08:18Z</dc:date>
    <item>
      <title>Java  Multiple Vulnerabilities</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/java-multiple-vulnerabilities/m-p/4343310#M734930</link>
      <description>&lt;BR /&gt;Dear all,&lt;BR /&gt;&lt;BR /&gt;I just received a warning on java vulnerabilities, CVE-2008-3339. The suggestion is to upgrade the java to 5.0 update 17.&lt;BR /&gt;&lt;BR /&gt;However currently the latest java in hpux is 1.5.0.14, which includes sun java 1.5.0.16FCS.&lt;BR /&gt;&lt;BR /&gt;Is it true that hpux java 1.5.0.14 can't fixes the vulnerabilities? And if it can't, when will the later version of java release to fix it?&lt;BR /&gt;&lt;BR /&gt;Thanks and regards,&lt;BR /&gt;Godchild.</description>
      <pubDate>Fri, 23 Jan 2009 04:03:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/java-multiple-vulnerabilities/m-p/4343310#M734930</guid>
      <dc:creator>godchild_ii</dc:creator>
      <dc:date>2009-01-23T04:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: Java  Multiple Vulnerabilities</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/java-multiple-vulnerabilities/m-p/4343311#M734931</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;Are you sure you got the correct CVE.&lt;BR /&gt;&lt;BR /&gt;CVE-20098-3339 actually talks about:&lt;BR /&gt;&lt;BR /&gt;QUOTE&lt;BR /&gt;search_result.cfm in Jobbex JobSite allows&lt;BR /&gt;remote attackers to obtain sensitive&lt;BR /&gt;information via unspecified vectors that&lt;BR /&gt;reveal the installation path in an error&lt;BR /&gt;message.&lt;BR /&gt;&lt;BR /&gt;It contains flaws that allow remote SQL&lt;BR /&gt;injection attacks and cross site scripting.&lt;BR /&gt;&lt;BR /&gt;SQLi occurs where the "jobstateid" and&lt;BR /&gt;"jobcountryid" don't properly sanitize input&lt;BR /&gt;submitted to the search_result.cfm script.&lt;BR /&gt;This may allow an attacker to inject or manipulate SQL queries in the backend database.&lt;BR /&gt;END QUOTE&lt;BR /&gt;&lt;BR /&gt;Could you please share the document where you&lt;BR /&gt;found reference to Java to 5.0 update 17&lt;BR /&gt;on HP-UX?&lt;BR /&gt;&lt;BR /&gt;The latest Java JDK/JRE at HP is&lt;BR /&gt;version 6.0.2.&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;&lt;BR /&gt;VK2COT</description>
      <pubDate>Fri, 23 Jan 2009 05:04:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/java-multiple-vulnerabilities/m-p/4343311#M734931</guid>
      <dc:creator>VK2COT</dc:creator>
      <dc:date>2009-01-23T05:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: Java  Multiple Vulnerabilities</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/java-multiple-vulnerabilities/m-p/4343312#M734932</link>
      <description>Hello VK2COT,&lt;BR /&gt;&lt;BR /&gt;Thank for your reply.&lt;BR /&gt;&lt;BR /&gt;Sorry for refering wrong ID.&lt;BR /&gt;&lt;BR /&gt;The vulnerabilities I am checking is VUPEN/ADV-2008-3339&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.vupen.com/english/advisories/2008/3339" target="_blank"&gt;http://www.vupen.com/english/advisories/2008/3339&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 23 Jan 2009 06:08:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/java-multiple-vulnerabilities/m-p/4343312#M734932</guid>
      <dc:creator>godchild_ii</dc:creator>
      <dc:date>2009-01-23T06:08:18Z</dc:date>
    </item>
  </channel>
</rss>

