Skip to main content

Our security team alerted us to the vulnerable version of the Java JRE used by commServe. According to them, multiple vulnerabilities were found in Oracle Java SE and malicious users can exploit these vulnerabilities to bypass security restrictions, obtain sensitive information, cause denial of service, gain privileges, execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. Security vulnerability in JSSE component can be exploited remotely to bypass security restrictions.
  2. Security vulnerability can be exploited remotely to bypass security restrictions.
  3. Vulnerability in JSSE component of Java SE can be exploited to cause denial of service.
  4. Vulnerability in Keytool component of Java SE can be exploited to obtain sensitive information;
  5. Security vulnerability in Hotspot component can be exploited remotely to bypass security restrictions.
  6. Vulnerability in Utility component of Java SE can be exploited to cause denial of service.
  7. Vulnerability in Swing component of Java SE can be exploited to cause denial of service.
  8. Vulnerability in JSSE component of Java SE can be exploited to obtain sensitive information;
  9. Vulnerability in ImageIO component of Java SE can be exploited to obtain sensitive information;
  10. Vulnerability in Libraries component of Java SE can be exploited to obtain sensitive information.
  11. A remote code execution vulnerability in Deployment component can be exploited remotely to execute arbitrary code.

 

As a CommVault Administrator, what would you do? How to proceed in these cases?

Source: 

https://threats.kaspersky.com/en/vulnerability/KLA12331/

Hello Eduardo,

 

For the Oracle Java SE vulnerabilities, you can simply uninstall Java from the CS, as we use Open JDK since SP16.

If you need to open CommCell Console remotely from your desktop, you can use netx.jar file method: https://documentation.commvault.com/commvault/v11_sp20/article?p=3838.htm


Byates, thank you, I don't want to find out days after removing the JRE that one of other Commvault installed software need it and the list of the Commvault installed software is big. 


Eduardo,

 

Oracle Java is not needed by Commvault software.  You will want to confirm it is not needed by Non-Commvault software, but if not, it is safe to remove.