Showing posts with label Java Software. Show all posts
Showing posts with label Java Software. Show all posts

Saturday, 21 March 2015

Oracle Stops Security Updates For Java 7


Oracle Java users warned that after April no more security updates are offered for Java 7, unless a special agreement is concluded. This runs the risk of a large number of users to sit with an unsupported version, unless they upgrade to Java 8.

In January PaaS provider Jelastic published an overview of the various Java versions that are in use. Then it turns out that 83% of users still using the Java version 7. Java 6 is already installed in 14% of users, while the latest version of Java, Java 8, was found in only 3% of the Java Users. Like Microsoft Windows XP organizations the opportunity to continue receiving updates while supporting stopped for consumers, Oracle also does this.

"As described in the Oracle JDK Support roadmap, Oracle will after April 2015 no updates for Java SE7 to publish public download site. Customers who need access to critical bug fixes and security updates as well as general support for Java SE 7 or older versions may have a long-term contract support for close, " said the software giant on its own website.

Wednesday, 21 January 2015

Oracle Java SSL 3.0 Switches Off


To protect users from attack Java, Oracle SSL 3.0 disabled in the software. The measure is part of the security update that appeared Tuesday. "This Critical Patch Update disables the standard use of SSL 3.0. SSL 3.0 will be considered an obsolete protocol and this situation is exacerbated by the POODLE-leak. As a result, this protocol widely attacked by malicious hackers," says Eric Maurice Oracle.

The POODLE-vulnerability in SSL 3.0 ensures that an attacker who between a user and the Internet to know places, for example in an open Wi-Fi network, can steal information from encrypted connections, such as session cookies. Maurice gives organizations advised to discontinue use of all SSL versions, as it is no longer the safe communication between systems can be trusted.

Also Oracle customers have to change their code and switch to a more secure protocol such as TLS 1.2. Oracle employee further notes that Oracle in the future SSL in all Oracle software will turn off. Besides disabling SSL 3.0 update also fixes 19 vulnerabilities in Java, which in the worst case, an attacker can give full control over the system.