Menu
With latest patches, Oracle signals no more free updates for Java 7

With latest patches, Oracle signals no more free updates for Java 7

The company released patches from 98 security issues in its products, 14 in Java

Oracle released patches for a total of 98 security issues across a wide range of products, including 14 in Java. This marks the last free patch for Java 7, users being encouraged to upgrade to version 8.

Three of the Java vulnerabilities patched Tuesday have the maximum severity score of 10 in the Common Vulnerability Scoring System (CVSS), which means that they can be exploited over the network without authentication and can lead to a full compromise of the system's confidentiality and integrity.

Twelve of the flaws affect the Java client, meaning they can potentially be exploited from the Web through the Java browser plug-in. One of them also affects Java server deployments and the remaining two affect the client and server deployments of the Java Secure Socket Extension (JSSE).

In order to address these vulnerabilities Oracle released Java 8 update 45 (Java 8u45), Java 7u79, Java 6u95 and Java 5u85. The Java 6 and 5 updates are only available to customers with long-term Java support contracts.

With this latest release, Java 7 has also reached end of life for public updates, so future security patches for this version of Java will also be available only to customers with special support contracts. Users who have automatic updates enabled in Java 7 have been prompted to upgrade to Java 8 since January.

The end of free Java 7 security patches is "huge news," according to John Matthew Holt, chief technology officer at application security firm Waratek, who believes that it will cause "enormous headache and disruption to millions of application owners around the world."

"Oracle's rapid end of life schedule for Java versions is great for innovation and language evolution," Holt said via email. "However, there is a dangerous tradeoff: now millions of Java 7 applications will have to defend themselves against code level vulnerabilities without the benefit of future fixes."

Aside from Java, as part of its April 2015 Critical Patch Update, Oracle fixed security flaws in the Oracle Database, Oracle Fusion Middleware, Oracle Hyperion, Oracle Enterprise Manager, Oracle E-Business Suite, Oracle Supply Chain Suite, Oracle PeopleSoft Enterprise, Oracle JDEdwards EnterpriseOne, Oracle Siebel CRM, Oracle Industry Applications, Oracle Java SE, Oracle Sun Systems Products Suite, Oracle MySQL and Oracle Support Tools.

Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Tags patchessecuritypatch managementExploits / vulnerabilitiesOracleWaratek

Slideshows

Top 50 defining moments of the New Zealand channel in 2016

Top 50 defining moments of the New Zealand channel in 2016

Reseller News looks back on a tumultuous 12 months for the New Zealand channel, assessing the fallout from a year of sizeable industry change. Whether it be local or global mergers and acquisitions, distribution deals or job changes, the channel that started the year differs somewhat to the one set to finish it - Reseller News assesses the key moments that made 2016.​

Top 50 defining moments of the New Zealand channel in 2016
​Hewlett Packard Enterprise honours high achieving NZ channel

​Hewlett Packard Enterprise honours high achieving NZ channel

Hewlett Packard Enterprise honoured its top performing Kiwi partners at the second running of its HPE Partner Awards in New Zealand, held at a glitzy ceremony in Auckland. Recognising excellence across eight categories - from distributors to resellers - the tech giant celebrated its first year as a standalone company, following its official split from HP in 2015.

​Hewlett Packard Enterprise honours high achieving NZ channel
Nutanix treats channel partners to Christmas cruise

Nutanix treats channel partners to Christmas cruise

Nutanix recently took to the seas for a Christmas Cruise around Sydney Harbour with its Australia and New Zealand staff, customers and partners to celebrate a stellar year for the vendor. With the sun out, they were all smiles and mingled over drinks and food.

Nutanix treats channel partners to Christmas cruise
Show Comments