Java Vulnerabilities Persist Despite Warnings

LOS ANGELES — Internet security experts have long advised computer users to use an anti-virus solution and to keep their software updated, but too often it seems that a lack of concern over these calls is leading to problems for businesses and consumers alike.

A recent whitepaper by trust-based security firm Bit9, entitled, “Java Vulnerabilities Report: Write Once, Pwn Anywhere,” is casting new light on the ongoing threats to the most widely deployed software ever.

Explaining that Java was originally released with the slogan “write once, run anywhere,” the report notes that the popularity of this technology underscore its cross-platform capabilities.

“Over time, Java has become ubiquitous on endpoints, so ‘run anywhere’ can be interpreted as referring to its ubiquity. Even as fewer websites and web applications require Java in order to operate properly, the technology is pervasive on virtually every end-user system,” the Bit9 report states. “For a variety of reasons, Java also has become a platform that is highly vulnerable to attack.”

The report notes that Java’s ubiquity and vulnerabilities have made it the technology most frequently exploited by cyber attackers, prompting Bit9 to take a closer look at the reasons behind this problem, incorporating data from many organizations.

The results of this initiative are both “surprising and concerning” to Bit9 which not only found that Java has become the most targeted endpoint technology, but that less than one percent of companies are running the latest version of Java.

The report also explains that most endpoints have multiple versions of Java installed, partly because the Java installation and update process does not remove the old versions, leading attackers to typically target old, vulnerable versions installed on the computer or other device.

“The solution is that organizations need to take a serious look at their use of Java,” Bit9 CTO Harry Sverdlove told eWEEK. “This is not just one of a million things that organizations can do to improve their security posture — this is the most attacked vector. They need to seriously consider what their policy is and where Java is deployed in their environment.”

Calling 2012 “The year of Java vulnerabilities,” a Kaspersky Security Bulletin names Oracle’s Java as being the most frequently exploited software by cybercriminals in 2012, with Java security holes responsible for half of all attacks. Contrast this figure to that of Microsoft’s Windows components and Internet Explorer browser, long called vulnerable, which were exploited in only three percent of incidents.

Kaspersky explains that exploit packs (malicious programs that attempt to infect a computer utilizing various vulnerabilities in popular software) are the main tool behind web-based attacks.

“Exploiting vulnerabilities is one of the primary methods used by cybercriminals to install malware on victims’ computers,” the Kaspersky Bulletin notes. “Cybercriminals exploit applications or software that have un-patched security vulnerabilities, which exist because either the individual or business have failed to patch their vulnerable applications with the latest security updates from vendors.”

According to Oracle’s Java software development lead Nandini Ramani, the company is working diligently to respond to the rise in reports of security vulnerabilities in Java, especially those that affect web browsers running Java, with a number of enhancements to the default security profile, while providing more control over security for end users.

“It is our belief that as a result of this ongoing security effort, we will decrease the exploitability and severity of potential Java vulnerabilities in the desktop environment and provide additional security protections for Java operating in the server environment,” Ramani said.

“The fact that a majority of observed environments apparently use significantly out-of-date versions of Java points to potential issues in how well the average organization manages its software as well as the large attack surface area presented by Java in the majority of organizations,” the Bit9 report concludes.

An infographic on Java based security threats is available for download here.

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Nebraska Legislature Passes Republican's Age Verification Bill With No Votes Against It

Nebraska’s unicameral legislature has passed the state’s version of the age verification bills being sponsored around the country by anti-porn religious conservative activists.

Performers in Meta Blacklisting Lawsuit Seek to Preserve Antitrust Claims

Adult Performance Artists Guild board officers Alana Evans, Kelly Pierce and Ruby have informed a California court that, although they want to drop their lawsuit claiming that Meta conspired with OnlyFans to blacklist rival premium fan platforms’ talent, they may still have antitrust claims that they may pursue in the future.

FSC, Co-Plaintiffs to Ask US Supreme Court to Review Constitutionality of Texas Age Verification Law

Free Speech Coalition (FSC) and its co-plaintiffs in the challenge to Texas’ controversial age verification law have filed a petition before the United States Court of Appeals for the 5th Circuit asking to stay its recent upholding the law because they intend to appeal to the U.S. Supreme Court to review the law’s constitutionality.

FSC Vows to Fight Florida Age Verification Law

Free Speech Coalition (FSC) issued a statement vowing to continue fighting Florida’s age verification law, which was signed by Gov. Ron DeSantis on Monday as part of a comprehensive bill targeting minors’ use of social media.

Kansas Republican Aims to Create New Bureaucracy to 'Investigate' Porn Websites

Republican state legislators succeeded Monday in moving forward Kansas’ version of the age verification bills being sponsored around the country by anti-porn religious conservative activists, despite serious concerns raised by House Democrats about the cost of establishing a new bureaucracy tasked with investigating websites for pornographic content.

SK Intertainment Launches 'Skinfluential Management' Agency, FansFuel Joint Venture

Mr. Skin/Mr. Man parent company SK Intertainment has launched new creator agency Skinfluential Management, as well as a new joint venture with Showbizz Media's creator stats and affiliate marketing platform, FansFuel.

Industry Attorney, Free Speech Champion Clyde DeWitt Passes Away at 75

Noted industry attorney Clyde DeWitt passed away on Friday in Las Vegas at 75, according to friends and colleagues.

APClips Names Avery Jane 'Creator of the Month'

APClips has named Avery Jane its Creator of the Month for March.

JustFor.fans Offers Gumroad Users Platform to Sell NSFW Artwork

JustFor.fans (JFF) is offering Gumroad users a platform to sell NSFW artwork after the latter banned adult content.

Live Cam Academy Offers Free Access to Educational Resources

Live Cam Academy is offering its educational resources for free to content creators and cam models.

Show More