Share

Related Stories

Top 5 Stories

News

Oracle fixes 21 flaws in Java SE, Java for Business

18 February 2011

Oracle is fixing 21 flaws in its Java SE and Java for Business products in its February critical patch update issued this week.

According to the company, 19 of the flaws affecting the Java Runtime Environment could be exploited remotely over a network without the need for a username and password. Eight of the flaws have the highest score of 10 on the company’s common vulnerability scoring system.

Oracle strongly recommended that customers apply fixes “as soon as possible” due to the “threat posed by a successful attack.”

Oracle security blogger Eric Maurice said that out of the 21 flaws, 13 affect Java client deployments, of which 12 can be exploited through untrusted Java Web Start applications and untrusted Java Applets, which run in the Java sandbox with limited privileges. One of these flaws can be exploited by running a standalone application.

Maurice went on to note that three of the 21 vulnerabilities affect Java server deployments only. These flaws can be exploited by supplying malicious data to APIs in the specified components, such as a web service. One of these flaws was the subject of a security alert sent out Feb. 8, he noted.

A recent report by Cisco found that in 2010 Java was three and a half times more exploited than Adobe PDF. “Even though Adobe received the lion’s share of attention, because of exploits targeting Adobe Reader and Acrobat, the reality is that exploits of Java caused a lot more problems over the year”, noted Mary Landesman, Cisco senior security threat researcher.
 

This article is featured in:
Application Security  •  Malware and Hardware Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.

We use cookies to operate this website and to improve its usability. Full details of what cookies are, why we use them and how you can manage them can be found by reading our Privacy & Cookies page. Please note that by using this site you are consenting to the use of cookies. ×