CF7 & JRE security updates?

Ask a Question related to Coldfusion Server Administration, Design and Development.

  1. #1

    Default CF7 & JRE security updates?

    CFMX 7.0.2 with the latest patches runs JRE 1.4.2_09 at it's core. There have
    been several Critical security issues with the JRE versions CFMX7. All of the
    Security bulletins from SUN suggest upgrading to 1.4.2_13 to protect yourself
    from these vulnerabilities.

    The main issue for me is we run machines that require that their patch level
    meet the 1.4.2_13 to meet our certification requirements. Is it possible to
    update the CF core to the newer version safely/reliably or does Adobe plan to
    address these issues with their application in a timely fashion since there are
    several agencies that must meet this same security requirement to stay in good
    standings?

    brentil Guest

  2. Similar Questions and Discussions

    1. How to get security updates?
      Hej, I have the following entries in my /etc/apt/sources.list: deb http://archive.ubuntu.com/ubuntu breezy main restricted universe multiverse...
    2. sp3 & security updates
      Since applying Office 2K Pro SP3 and the September security patches the hyperlinks no longer work in Publisher. This includes the links in Help. ...
    3. Security Updates
      I am currently using Norton Internet Security. Do I need to download any Security Updates?
    4. new XP security updates
      Recently I tried to download the security update from Microsoft 818043 for my XP system. It totally froze any internet connectivity for me. There...
    5. security updates.
      microsoft baseline security analyzer says i am missing three update that i download and instard. the three up date are Q323255 814078 and Q306460...
  3. #2

    Default Re: CF7 & JRE security updates?

    You can configure CF to use an external JRE. Depending on your version you'll either do it in the admin or in your jvm.config file.
    ke4pym Guest

  4. #3

    Default Re: CF7 & JRE security updates?

    [q]Originally posted by: ke4pym
    You can configure CF to use an external JRE. Depending on your version you'll
    either do it in the admin or in your jvm.config file.[/q]

    The problem is the insecure version of the application is still on the
    machine. For the machine to meet DoD requirements we must fulfill a required
    set of standards, and the fix for this issue is in the list.

    brentil Guest

  5. #4

    Default Re: CF7 & JRE security updates?

    On windows machines you must upgrade to the JDK version of the JRE, you cannot
    use the JRE version. It lacks the server JVM required.
    Unix/Linux machines generally install the JRE with a server JVM option.
    CFMX 6 & 7 have already been certified on 1.4.2_11 and run fine. We would not
    expect any issues using the 1.4.2_13 JVM and will clearly support that
    configuration since it is required to resolve security issues.
    I am not sure if and when we will certify a newer JDK than 1.4.2_11. It is
    impossible to certify every point release of ever JVM (OS, chipset, etc...)

    ksmith Guest

  6. #5

    Default Re: CF7 & JRE security updates?

    [q]Originally posted by: ksmith
    On windows machines you must upgrade to the JDK version of the JRE, you cannot
    use the JRE version. It lacks the server JVM required.
    Unix/Linux machines generally install the JRE with a server JVM option.
    CFMX 6 & 7 have already been certified on 1.4.2_11 and run fine. We would not
    expect any issues using the 1.4.2_13 JVM and will clearly support that
    configuration since it is required to resolve security issues.
    I am not sure if and when we will certify a newer JDK than 1.4.2_11. It is
    impossible to certify every point release of every JVM (OS, chipset, etc...)[/q]

    Thanks for the reply. Following the DST information we've taken and upgraded
    out CFMX 7.0.2 to now use the 1.4.2_13 version of the JDK. We've had our
    development server running it for about a week now, so far our developers have
    not run into any issues. I even removed the old JRE dir from inside of CFMX
    7.0.2 to test if that could be done as well. So far no issues from that either.

    brentil Guest

  7. #6

    Default Re: CF7 & JRE security updates?

    Just wanted to mention we've been running 1.4.2_13 on our development machine since my last post with no issues. We've rolled out the same version to 4 production servers with no issues as well.
    brentil Guest

Posting Permissions

  • You may not post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139