Skip to main content
Solved

Issue with Java JRE 1.8.x


Forum|alt.badge.img+9

Our security team alerted us to the vulnerable version of the Java JRE used by commServe. According to them, multiple vulnerabilities were found in Oracle Java SE and malicious users can exploit these vulnerabilities to bypass security restrictions, obtain sensitive information, cause denial of service, gain privileges, execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. Security vulnerability in JSSE component can be exploited remotely to bypass security restrictions.
  2. Security vulnerability can be exploited remotely to bypass security restrictions.
  3. Vulnerability in JSSE component of Java SE can be exploited to cause denial of service.
  4. Vulnerability in Keytool component of Java SE can be exploited to obtain sensitive information;
  5. Security vulnerability in Hotspot component can be exploited remotely to bypass security restrictions.
  6. Vulnerability in Utility component of Java SE can be exploited to cause denial of service.
  7. Vulnerability in Swing component of Java SE can be exploited to cause denial of service.
  8. Vulnerability in JSSE component of Java SE can be exploited to obtain sensitive information;
  9. Vulnerability in ImageIO component of Java SE can be exploited to obtain sensitive information;
  10. Vulnerability in Libraries component of Java SE can be exploited to obtain sensitive information.
  11. A remote code execution vulnerability in Deployment component can be exploited remotely to execute arbitrary code.

 

As a CommVault Administrator, what would you do? How to proceed in these cases?

Source: 

https://threats.kaspersky.com/en/vulnerability/KLA12331/

Best answer by byates

Eduardo,

 

Oracle Java is not needed by Commvault software.  You will want to confirm it is not needed by Non-Commvault software, but if not, it is safe to remove.

View original
Did this answer your question?
If you have a question or comment, please create a topic

3 replies

byates
Vaulter
Forum|alt.badge.img+3
  • Vaulter
  • 19 replies
  • March 21, 2022

Hello Eduardo,

 

For the Oracle Java SE vulnerabilities, you can simply uninstall Java from the CS, as we use Open JDK since SP16.

If you need to open CommCell Console remotely from your desktop, you can use netx.jar file method: https://documentation.commvault.com/commvault/v11_sp20/article?p=3838.htm


Forum|alt.badge.img+9

Byates, thank you, I don't want to find out days after removing the JRE that one of other Commvault installed software need it and the list of the Commvault installed software is big. 


byates
Vaulter
Forum|alt.badge.img+3
  • Vaulter
  • 19 replies
  • Answer
  • March 21, 2022

Eduardo,

 

Oracle Java is not needed by Commvault software.  You will want to confirm it is not needed by Non-Commvault software, but if not, it is safe to remove.


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings