Tenable Research Release Highlights

Forum Discussion

Anonymous's avatar
Anonymous
6 years ago

Improved Accuracy of Oracle Java Detection on Windows...

Improved Accuracy of Oracle Java Detection on Windows

Change

Nessus Plugin 33545 finds Oracle Java Runtime Environments (JREs) on Windows platforms. Multiple vendors provide JREs, and security advisories for one vendor do not apply to others. This plugin was including some OpenJDK and IBM Java executables in these reports. With this change, these executables will no longer be misidentified as Oracle Java.

Impact

Customers should expect more accurate identification of Oracle Java installs, potentially resulting in fewer vulnerability reports.

Plugin

33545 - Oracle Java Runtime Environment (JRE) Detection

Target Release Date

16 September 2019

Additional Notes

If plugin debugging is enabled, these non-Oracle Java instances will be noted in the logs.

5 Replies

  • cezar1's avatar
    cezar1
    Connect Captain

    Will there be plugin showing non-Oracle JRE implementations installed on Windows systems?

    • Anonymous's avatar
      Anonymous

      More research on how the version is represented needs to be done, but yes, we will work to support OpenJDK and IBM Java on Windows.

  • ​Thanks for the info @Matt Everson​ - I would request that when multiple versions of Java is detected in the output we display installed path of all Java versions. I had challenges when I was new to Nessus Pro, I used to get this vulnerability but the output used to have only 1 installed java path.