Oracle has said that it would deliver 14 patches on Tuesday, in order to address serious security problems with the Java platform.
“Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Critical Patch Update fixes as soon as possible,” an advisory states.
The critical patches will apply to systems running JRE and JDK versions 5.0 (Update 35 and earlier), 6.0 (Update 32 and earlier), and 7.0 (Update 4 and earlier). The update also applies to SDK and JRE version 1.4.2_37 and earlier, as well as JavaFX 2.1.
It’s worth a mention that the at least one patch has earned a CVSS score of 10, meaning it has the highest level of importance. Of the 14 patches to be released, 12 of them are remotely exploitable without any authentication.
Based on Oracle’s information, several of the patches address issues within JRE, a commonly targeted component in Java itself.
It goes without saying really that the patches should be applied immediately, but the best bet is that if Java isn’t used or needed, it shouldn’t be installed in the first place.
The patches are set to ship Tuesday afternoon (June 12).
Related: Endless Exploit Attempts Underline Importance of Timely Java Patching
More from Steve Ragan
- Anonymous Claims Attack on IP Surveillance Firm Brickcom, Leaks Customer Data
- Workers Don’t Trust Employers with Personal Data: Survey
- Root SSH Key Compromised in Emergency Alerting Systems
- Morningstar Data Breach Impacted 184,000 Clients
- Microsoft to Patch Seven Flaws in July’s Patch Tuesday
- OpenX Addresses New Security Flaws with Latest Update
- Ubisoft Breached: Users Urged to Change Passwords
- Anonymous Targets Anti-Anonymity B2B Firm Relead.com
Latest News
- Dozens of Malicious Extensions Found in Chrome Web Store
- What if the Current AI Hype Is a Dead End?
- Microsoft Makes SMB Signing Default Requirement in Windows 11 to Boost Security
- Zyxel Urges Customers to Patch Firewalls Against Exploited Vulnerabilities
- Gigabyte Rolls Out BIOS Updates to Remove Backdoor From Motherboards
- SBOMs – Software Supply Chain Security’s Future or Fantasy?
- Ransomware Group Used MOVEit Exploit to Steal Data From Dozens of Organizations
- Cybersecurity M&A Roundup: 36 Deals Announced in May 2023
