CIO Today

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
Daily Briefing for Technology's Top Decision-Makers
Vblock™ Systems:
Advanced converged infrastructure
increases productivity & lowers costs.

www.vce.com
Wednesday, April 23rd 
24/7/365 Network Uptime!
This ad will display for the next 20 seconds. Please click for more information, or scroll down to pass the ad, or Close Ad.
Trending Topics:   Security Heartbleed Big Data Cloud Computing Windows XP Data Centers OS X Mavericks
Home
Enterprise Software
Enterprise Hardware
Big Data
Network Security
Cloud Computing
CRM Systems
Data Storage
Operating Systems
Communications
CIO Issues
Mobile Tech
Chips & Processors
World Wide Web
Business Briefing
After Hours
Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Network Security

Oracle Rushes Out New Java Zero-Day Patches

Oracle Rushes Out New Java Zero-Day Patches
March 5, 2013 2:08PM

Bookmark and Share
"The smart and safe approach to using Java is to use a two-browser approach so that you have one browser without Java for your daily Web surfing and use a different browser strictly for the use of Java," said security researcher Jerome Segura. "An even safer approach for enterprises is to use dedicated virtual machines for Web browsing with Java."

BMC is redefining the relationship between I.T. and business. Now I.T. can provide easy access to business services, support and applications -- anywhere, anytime, and from any device. Meaning a more efficient business and an even more innovative I.T. Learn more here.

Oracle just rolled out a new Database Appliance, complete with virtualization, but news of more Java security woes may be overshadowing the announcement. Oracle has released a new Java update to patch zero-day vulnerabilities.

According to Oracle, the Security Alert addresses security issues CVE-2013-1493 and another vulnerability affecting Java running in web browsers. Oracle was quick to point out that the vulnerabilities do not apply to Java running on servers, standalone Java desktop applications or embedded Java applications. They also do not affect Oracle server-based software.

"These vulnerabilities may be remotely exploitable without authentication, i.e., they may be exploited over a network without the need for a username and password," Oracle said in its security alert. "For an exploit to be successful, an unsuspecting user running an affected release in a browser must visit a malicious web page that leverages these vulnerabilities. Successful exploits can impact the availability, integrity, and confidentiality of the user's system."

Skirting Java

"Recent attacks against Apple, Facebook and Twitter all used Java zero-days to penetrate the companies' networks and install Remote Administration Trojans," Malwarebytes researcher Jerome Segura told us. "What is important to realize is that no matter how up-to-date those systems were, even with anti-virus and firewall, they still got compromised. This shows just how dangerous Web exploits and zero-days are."

The most common advice is to remove or disable Java however, noted Segura, however many applications depend on Java and removing it would be a problem.

"The smart and safe approach to using Java is to use a two-browser approach so that you have one browser without Java for your daily Web surfing and use a different browser strictly for the use of Java," he said. "An even safer approach for enterprises is to use dedicated virtual machines for Web browsing with Java, and other plug-ins, for that matter."

Oracle Feeling Java Heat

Oracle has been working hard to keep Java patched in 2013. Oracle patched at least 55 flaws in Java in February. In January, Oracle offered a Java 7 update that fixed zero-day flaws that were being actively exploited in the wild.

"The company intended to include a fix for CVE-2013-1493 in the April 16, 2013, Critical Patch Update for Java SE (note that Oracle recently announced its intent to have an additional Java SE security release on this date in addition to those previously scheduled in June and October of 2013)," Eric Maurice, Oracle's director of Software Assurance, wrote in a blog post. "However, in light of the reports of active exploitation of CVE-2013-1493, and in order to help maintain the security posture of all Java SE users, Oracle decided to release a fix for this vulnerability and another closely related bug as soon as possible through this Security Alert."

Oracle and Maurice are feeling the heat. He said Oracle is committed to accelerating the release of security fixes for Java SE, particularly to help address the security-worthiness of Java running in browsers. The quick release of this Security Alert, the higher number of Java SE fixes included in recent Critical Patch Updates, he said, and the announcement of an additional security release date for Java SE -- the April 16 Critical Patch Update for Java SE -- are examples of that commitment.

Tell Us What You Think
Comment:

Name:



 Network Security
1. Verizon Report Exposes Cyberthreats
2. How Are Web Sites Post-Heartbleed?
3. White House Updating Privacy Policy
4. Target Hackers May Be Tough To Find
5. Heartbleed Exploit Could Cost Millions




 Most Popular Articles
1. BlackBerry Drops T-Mobile After Nasty Spat
2. Cisco, IBM Launch Internet of Things Consortium
3. Salesforce CRM Gets Industry Specific for Internet of Customers
4. Intel Bets on Cloudera for Big Data Analytics
5. SAP HANA Data Warehouse App Gets Faster Analytics

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Hortonworks, Concurrent To Partner
  Microsoft, BMC Targeting VMware
  AT&T in $500M Net Video Partnership
  Verizon Report Exposes Cyberthreats
  Samsung: $2.2B Too Much for Apple

 Technology Marketplace
Business Intelligence
Get real-time, cloud-based information services with Neustar.
 
Cloud Computing
Next Generation Data Center Is Here! Vblock™ Systems from VCE
 
Contact Centers
HP delivers the future of the contact center with HP Qfiniti 10.
 
Data Storage
Next Generation Data Center Is Here! Vblock™ Systems from VCE
Barium Ferrite (BaFe) is the future of tape.
2.5" Enterprise-class SATA & SAS SSDs for server & storage applications
 
Enterprise Hardware
Barium Ferrite (BaFe) is the future of tape.
2.5" Enterprise-class SATA & SAS SSDs for server & storage applications
 
Hardware
Protect your network with APC Smart-UPS battery backup
 
Network Security
Protect your network with APC Smart-UPS battery backup
 

Network Security Spotlight
Verizon Data Breach Report Exposes Top Threats
Beyond Heartbleed, there are cyberthreats vying to take down enterprise networks, corrupt smartphones, and wreak havoc on businesses. Verizon is exposing these threats in a new report.
 
Where Do Web Sites Stand, Post-Heartbleed?
A security firm says the vast majority of Web sites have patched themselves to protect against the Heartbleed bug, but now there are questions raised on the reliability of open-source programs.
 
White House Updating Online Privacy Policy
A new Obama administration privacy policy explains how the government will gather the user data of online visitors to WhiteHouse.gov, mobile apps and social media sites, saying much is in the public domain.
 
Navigation
CIO Today
Home/Top News | Enterprise Software | Enterprise Hardware | Big Data | Network Security | Cloud Computing | CRM Systems
Data Storage | Operating Systems | Communications | CIO Issues | Mobile Tech | Chips & Processors | World Wide Web
Business Briefing | After Hours | Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 CIO Today. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.