Secunia CSI7
Advisories
Research
Forums
Create Profile
Our Commitment
PSI
PSI API
CSI
OSI
xSI
Vulnerabilities
Programs
Open Discussions
My Threads
Create Thread
Statistics
About

Forum Thread: Cant remove JRE because its bundled with another application

You are currently viewing a forum thread in the Secunia Community Forum. Please note that opinions expressed here are not of Secunia but solely reflect those of the user who wrote it.

This thread was submitted in the following forum:
PSI

This thread has been marked as locked.
Jmann Cant remove JRE because its bundled with another application
Member 22nd Apr, 2009 09:19
Ranking: 0
Posts: 5
User Since: 22nd Apr, 2009
System Score: N/A
Location: N/A
What to do? Sun Java JRE 1.5x/5.x and Java Web Start 5.x are listed in Secunia PSI as insecure. The problem is that they are bundled with SPSS which is a statistics software that im using in my work as a student at the university. The installation paths are c:\Program Files\SPSSInc\Statistics17\JRE\bin\java.exe and c:\Program Files\SPSSInc\Statistics17\JRE\bin\javaws.exe. Is there any way to remove these without uninstalling SPSS? There are no updates availiable for SPSS just yet. There are no tabs in add or remove programs either.

OldGrantonian RE: Cant remove JRE because its bundled with another application
Member 22nd Apr, 2009 14:18
Score: 0
Posts: 7
User Since: 27th Feb 2009
System Score: N/A
Location: N/A
There are some very bright techies on this forum who will eventually help you. But before they (probably correctly) ask you to do something that might destroy the existing evidence, I would be most grateful if you could do me a favour, for my own education :)

Please look in "Environment Variables" to see if there is a pointer to the "JRE\bin" location. I'm no techy, but I suspect that if Java is bundled with an application, the pointer to "JRE\bin" will not be hard-coded into the application. Instead it will be in "Environment Variables".

Here's how to find "Environment Variables" (you probably already know):

Control Panel > System > Advanced System Settings

In the "System Properties" dialog box, in the "Advanced" tab, you will see a button, "Environment Variables"

In either the "User Variables" or "System Variables", you will see "PATH" or "path".

Please let me know if there is a pointer to "JRE\bin". If yes, please tell me the complete pointer.

BTW: I suspect that you can simply install an up-to-date JRE in, for example, "Program Files", and edit "PATH" or "path" to point to the new JRE location. But that's for the forum techies to decide, not me.

The advantage of an independent location is that the JRE is accessible by any application, not simply SPSS :)
Was this reply relevant?
+0
-0
Jmann RE: Cant remove JRE because its bundled with another application
Member 22nd Apr, 2009 15:25
Score: 0
Posts: 5
User Since: 22nd Apr 2009
System Score: N/A
Location: N/A
Im sorry but theres no pointer to JRE/bin in the Environment Variables, only pointers to systemroot/system32 folders and a few more. I do of course have an updated version of java installed. And btw im a real computer noob!
Was this reply relevant?
+0
-0
OldGrantonian RE: Cant remove JRE because its bundled with another application
Member 22nd Apr, 2009 17:35
Score: 0
Posts: 7
User Since: 27th Feb 2009
System Score: N/A
Location: N/A
on 22nd Apr, 2009 15:25, Jmann wrote:
And btw im a real computer noob!


No boasting please :)

I'm an even realer computer noob.

But as long as the A-team are still sleeping, here are some more questions.

on 22nd Apr, 2009 15:25, Jmann wrote:
I do of course have an updated version of java installed.


I'm not sure how any application can find your Java if it's not in the path.

As an experiment, please temporarily rename your java.exe and javaw.exe in the SPSS hierarchy.

The easiest way to rename a file is to append "$"

(Note that you only need to remove the "$" to return to your original configuration.)

So the filenames are now java.exe$ and javaws.exe$

Can you now run your SPSS application? Does it work?

BTW: If it works, it's finding the updated Java. If it doesn't work, it's still trying to find the EXE files with the "$" added.
Was this reply relevant?
+0
-0
GoneToPlaid RE: Cant remove JRE because its bundled with another application
Member 22nd Apr, 2009 17:58
Score: 5
Posts: 71
User Since: 1st Apr 2009
System Score: 100%
Location: Atlanta, US
on 22nd Apr, 2009 09:19, Jmann wrote:
What to do? Sun Java JRE 1.5x/5.x and Java Web Start 5.x are listed in Secunia PSI as insecure. The problem is that they are bundled with SPSS which is a statistics software that im using in my work as a student at the university. The installation paths are c:\Program Files\SPSSInc\Statistics17\JRE\bin\java.exe and c:\Program Files\SPSSInc\Statistics17\JRE\bin\javaws.exe. Is there any way to remove these without uninstalling SPSS? There are no updates availiable for SPSS just yet. There are no tabs in add or remove programs either.


Well, here is what I would try...

1. Reinstall the latest Java6 Update 13 or whatever it is. Why? Reinstalling will make sure that this latest Java version is what is registered with the system and in your web browsers.

2. Then go to Control Panel and launch the Java icon. Then click on JAVA in the Java Control Panel popup interface control. Then delete any listings for older versions of Java which are shown when you click View for the Java Applet Runtime Settings and the Java Application Runtime Settings. Then click OK and then close the Java Control Panel.

3. Delete the JRE directory from your Statistics17 directory. Don't do a shift-Delete. Instead, delete so that these files (for now) get moved to the Recycle Bin.

4. Now try your program and see if it still works just fine.

The worst thing that can happen is that you will have to reinstall your program.

:)
Was this reply relevant?
+0
-0
Jmann RE: Cant remove JRE because its bundled with another application
Member 22nd Apr, 2009 19:04
Score: 0
Posts: 5
User Since: 22nd Apr 2009
System Score: N/A
Location: N/A
Last edited on 22nd Apr, 2009 19:05
OldGrantonian, I tried renaming the files and SPSS did work, but i dont know if that really is the solution to the problem.

And GoneToPlaid, I reinstalled Java 6 13. When I then opened the java icon in the control panel and viewed the listings of java versions no older versions were shown.

I still tried deleting the JRE directory from the statistics17 directory, but now SPSS wouldnt run, so i restored it.

Anyways, thanks for the suggestions so far, and keep em coming!
Was this reply relevant?
+0
-0
GoneToPlaid RE: Cant remove JRE because its bundled with another application
Member 22nd Apr, 2009 21:06
Score: 5
Posts: 71
User Since: 1st Apr 2009
System Score: 100%
Location: Atlanta, US
Okay. Two things occur to me.

First, check to see if the SPSS program has any applet files somewhere in its JRE directory. Maybe you can move those applet files to Java6's applet directory under the Java directory in Program Files?

Second, since the Java6 Java Control Panel doesn't contain any info about the older version of Java installed by SPSS, you should be safe to tell Secunia PSI to simply ignore the c:\Program Files\SPSSInc\Statistics17\JRE directory. After all, if these older java files aren't registered within your OS, then malware and virus don't have an easy way to find these older Java files since they aren't in your OS's registry.

Well, thats my thinking for what its worth.

:)
Was this reply relevant?
+0
-0
wr RE: Cant remove JRE because its bundled with another application
Contributor 23rd Apr, 2009 01:31
Score: 308
Posts: 736
User Since: 30th Mar 2008
System Score: 100%
Location: US
Last edited on 23rd Apr, 2009 01:32
@ Jmann You might want to check out the enclosed link, I think the #1 link on this website will answer all your questions-briefly new versions are compatible w/old & vendors/developers need to be notified so their code can be rectified. But please check it out & satisfy yourself with the correct solution for you. http://java.com/en/download/help/index.xml

Regards, wr

--
HP Pavilion Slimline s3020n
Windows Vista Home Premium SP2 32 bit
AMD 64 Athlon X2
Firefox 24.4.0 ESR
The weakest link of a computer system is always sitting in front of the monitor.
Was this reply relevant?
+0
-0
Jmann RE: Cant remove JRE because its bundled with another application
Member 23rd Apr, 2009 09:31
Score: 0
Posts: 5
User Since: 22nd Apr 2009
System Score: N/A
Location: N/A
GoneToPlaid: Im a computer noob and I dont even know exactly what an applet file is. If u mean files that are executable in the JRE directory, or if u mean files in the applet directory, then no SPSS does not have any of these. I dont know if i feel comfortable by ignoring it either, but thanks for your help.

wr: I dont think I got that big of a chance to convince SPSS to release a new version with updated java, also i doubt that the program is incompatible with the latest version now anyways. Thanks anyway.

I really want to get rid of this threat (if it still is a threat), so keep the ideas coming!
Was this reply relevant?
+0
-0
Maurice Joyce RE: Cant remove JRE because its bundled with another application
Handling Contributor 25th Apr, 2009 23:44
Score: 11580
Posts: 8,899
User Since: 4th Jan 2009
System Score: N/A
Location: UK
Apart from trying what @GoneToPlaid suggested not sure there is a solution.

The problem lies with SPSS.

I suspect they have updated. From my research what U have forgotton to mention is that SPSS Statistics 17 has been upgraded to PASW Statistics 17.
Once U buy the upgrade the problem should disappeared.

It is unlikely SPSS will ever update your version & I am surprised PSI is not showing it as End of Life.

--
Maurice

Windows 7 SP1 64 Bit OS
HP Intel Pentium i7
IE 11 for Windows 7 SP1
16GB RAM
Was this reply relevant?
+0
-0
Jmann RE: Cant remove JRE because its bundled with another application
Member 26th Apr, 2009 18:01
Score: 0
Posts: 5
User Since: 22nd Apr 2009
System Score: N/A
Location: N/A
As said many times before im such a computer tool i dont know even what gonetoplaid meant. As for upgrading SPSS, we get this program for free at the university, and the version im using is the latest they have, and im not gonna buy it myself (its friggin expensive). So theres no solution then? How dangerous is it to have this on my computer?
Was this reply relevant?
+0
-0
GoneToPlaid RE: Cant remove JRE because its bundled with another application
Member 26th Apr, 2009 19:09
Score: 5
Posts: 71
User Since: 1st Apr 2009
System Score: 100%
Location: Atlanta, US
on 26th Apr, 2009 18:01, Jmann wrote:
As said many times before im such a computer tool i dont know even what gonetoplaid meant. As for upgrading SPSS, we get this program for free at the university, and the version im using is the latest they have, and im not gonna buy it myself (its friggin expensive). So theres no solution then? How dangerous is it to have this on my computer?


I don't think that there is any danger since it appears that only the SPSS program itself looks for the older JRE. From what you have already mentioned, the older JRE doesn't even appear to be registered with the operating system. That being the case, there is no danger. You can tell PSI to ignore the path to these files.
Was this reply relevant?
+0
-0

This thread has been marked as locked.


 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Reports
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2014 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability