Forum Discussion
Improved Accuracy of Oracle Java Detection on Windows...
Improved Accuracy of Oracle Java Detection on Windows
Change
Nessus Plugin 33545 finds Oracle Java Runtime Environments (JREs) on Windows platforms. Multiple vendors provide JREs, and security advisories for one vendor do not apply to others. This plugin was including some OpenJDK and IBM Java executables in these reports. With this change, these executables will no longer be misidentified as Oracle Java.
Impact
Customers should expect more accurate identification of Oracle Java installs, potentially resulting in fewer vulnerability reports.
Plugin
33545 - Oracle Java Runtime Environment (JRE) Detection
Target Release Date
16 September 2019
Additional Notes
If plugin debugging is enabled, these non-Oracle Java instances will be noted in the logs.
5 Replies
- cezar1Connect Captain
Will there be plugin showing non-Oracle JRE implementations installed on Windows systems?
- Anonymous
More research on how the version is represented needs to be done, but yes, we will work to support OpenJDK and IBM Java on Windows.
- Anonymous
Thanks for sharing.
Useful information
Thanks for the info @Matt Everson - I would request that when multiple versions of Java is detected in the output we display installed path of all Java versions. I had challenges when I was new to Nessus Pro, I used to get this vulnerability but the output used to have only 1 installed java path.