{"affected":[{"ecosystem_specific":{"binaries":[{"java-1_7_0-ibm":"1.7.0_sr10.80-65.60.1","java-1_7_0-ibm-alsa":"1.7.0_sr10.80-65.60.1","java-1_7_0-ibm-devel":"1.7.0_sr10.80-65.60.1","java-1_7_0-ibm-jdbc":"1.7.0_sr10.80-65.60.1","java-1_7_0-ibm-plugin":"1.7.0_sr10.80-65.60.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Point of Sale 11 SP3","name":"java-1_7_0-ibm","purl":"pkg:rpm/suse/java-1_7_0-ibm&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.7.0_sr10.80-65.60.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for java-1_7_0-ibm fixes the following issues:\n\n- Update to Java 7.0 Service Refresh 10 Fix Pack 80\n  [bsc#1182186, bsc#1181239, CVE-2020-27221, CVE-2020-14803]\n  * CVE-2020-27221: Potential for a stack-based buffer overflow\n    when the virtual machine or JNI natives are converting from\n    UTF-8 characters to platform encoding.\n  * CVE-2020-14803: Unauthenticated attacker with network access\n    via multiple protocols allows to compromise Java SE.\n","id":"SUSE-SU-2021:14640-1","modified":"2021-02-23T12:04:59Z","published":"2021-02-23T12:04:59Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2021/suse-su-202114640-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181239"},{"type":"REPORT","url":"https://bugzilla.suse.com/1182186"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-14803"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-27221"}],"related":["CVE-2020-14803","CVE-2020-27221"],"summary":"Security update for java-1_7_0-ibm","upstream":["CVE-2020-14803","CVE-2020-27221"]}