Our security team alerted us to the vulnerable version of the Java JRE used by commServe. According to them, multiple vulnerabilities were found in Oracle Java SE and malicious users can exploit these vulnerabilities to bypass security restrictions, obtain sensitive information, cause denial of service, gain privileges, execute arbitrary code.
Below is a complete list of vulnerabilities:
- Security vulnerability in JSSE component can be exploited remotely to bypass security restrictions.
- Security vulnerability can be exploited remotely to bypass security restrictions.
- Vulnerability in JSSE component of Java SE can be exploited to cause denial of service.
- Vulnerability in Keytool component of Java SE can be exploited to obtain sensitive information;
- Security vulnerability in Hotspot component can be exploited remotely to bypass security restrictions.
- Vulnerability in Utility component of Java SE can be exploited to cause denial of service.
- Vulnerability in Swing component of Java SE can be exploited to cause denial of service.
- Vulnerability in JSSE component of Java SE can be exploited to obtain sensitive information;
- Vulnerability in ImageIO component of Java SE can be exploited to obtain sensitive information;
- Vulnerability in Libraries component of Java SE can be exploited to obtain sensitive information.
- A remote code execution vulnerability in Deployment component can be exploited remotely to execute arbitrary code.
As a CommVault Administrator, what would you do? How to proceed in these cases?
Source: