Secunia CSI7
Advisories
Research
Forums
Create Profile
Our Commitment
PSI
PSI API
CSI
OSI
xSI
Vulnerabilities
Programs
Open Discussions
My Threads
Create Thread
Statistics
About

Forum Thread: Insecure Program Sun Java JRE 1.5.x/5.x

You are currently viewing a forum thread in the Secunia Community Forum. Please note that opinions expressed here are not of Secunia but solely reflect those of the user who wrote it.

This thread was submitted in the following forum:
Programs

Relating to this vendor:
Sun Microsystems
And, this specific program:
Oracle Java JRE 1.5.x / 5.x

This thread has been marked as locked.
Litisha Insecure Program Sun Java JRE 1.5.x/5.x
Member 28th Nov, 2008 01:44
Ranking: 0
Posts: 21
User Since: 27th Nov, 2008
System Score: N/A
Location: N/A
I don't quite understand. Can anyone help me. I read the forum and I uninstalled my Java and reinstalled the updated version. I currently have the most updated version, version 6 update 10. I rescanned my secunia and it still shows the Sun Java JRE 1.5.x/5.x as being still not being patched.

Thank you

BigDave_39 RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 28th Nov, 2008 08:03
Score: 0
Posts: 177
User Since: 26th Nov 2008
System Score: N/A
Location: Washington, DC, US
on 28th Nov, 2008 01:44, Litisha wrote:
I don't quite understand. Can anyone help me. I read the forum and I uninstalled my Java and reinstalled the updated version. I currently have the most updated version, version 6 update 10. I rescanned my secunia and it still shows the Sun Java JRE 1.5.x/5.x as being still not being patched.


Try looking at the paths where the PSI detected your installation of Java JRE - it may give you an idea to why it is being found.

You can also copy and paste the path into this thread.

--
Big Dave
Was this reply relevant?
+0
-0
This user no longer exists RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 29th Nov, 2008 10:41
Sun Java is terrible at updating as it leaves vulnerable versions on the hard drive.

Go to Add/Remove programs and un-install all versions of Sun Java then reboot.

Download JavaRa then run it to have it remove what it finds:
http://raproducts.org

Then install the latest Sun Java v6 r10
Was this reply relevant?
+1
-0
Litisha RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 30th Nov, 2008 00:34
Score: 0
Posts: 21
User Since: 27th Nov 2008
System Score: N/A
Location: N/A
YoKenny:

Thanks for your help, it didn't quite work but at least I have the javara for future downloads, I found that java was also in another program.

June
Was this reply relevant?
+0
-0
Litisha RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 30th Nov, 2008 00:36
Score: 0
Posts: 21
User Since: 27th Nov 2008
System Score: N/A
Location: N/A
on 28th Nov, 2008 08:03, BigDave_39 wrote:
Try looking at the paths where the PSI detected your installation of Java JRE - it may give you an idea to why it is being found.

You can also copy and paste the path into this thread.



Thank you so much, I finally figured out what you meant. I went to the advanced screen & pull up the technicals and found the path to the other program, I cut and pasted from your instructions and it worked.
Was this reply relevant?
+0
-0
ella larsen RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 29th Mar, 2009 11:46
Score: 0
Posts: 2
User Since: 9th Jan 2009
System Score: N/A
Location: N/A
on 28th Nov, 2008 01:44, Litisha wrote:
I don't quite understand. Can anyone help me. I read the forum and I uninstalled my Java and reinstalled the updated version. I currently have the most updated version, version 6 update 10. I rescanned my secunia and it still shows the Sun Java JRE 1.5.x/5.x as being still not being patched.

Thank you

Was this reply relevant?
+0
-0
ella larsen RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 29th Mar, 2009 11:47
Score: 0
Posts: 2
User Since: 9th Jan 2009
System Score: N/A
Location: N/A
on 28th Nov, 2008 01:44, Litisha wrote:
I don't quite understand. Can anyone help me. I read the forum and I uninstalled my Java and reinstalled the updated version. I currently have the most updated version, version 6 update 10. I rescanned my secunia and it still shows the Sun Java JRE 1.5.x/5.x as being still not being patched.

Thank you

Was this reply relevant?
+0
-0
mskuda RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 29th Mar, 2009 12:18
Score: 0
Posts: 3
User Since: 14th Mar 2009
System Score: N/A
Location: N/A
on 28th Nov, 2008 01:44, Litisha wrote:
I don't quite understand. Can anyone help me. I read the forum and I uninstalled my Java and reinstalled the updated version. I currently have the most updated version, version 6 update 10. I rescanned my secunia and it still shows the Sun Java JRE 1.5.x/5.x as being still not being patched.

Thank you

Was this reply relevant?
+0
-0
Tinkywinky RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 29th Mar, 2009 13:55
Score: 0
Posts: 1
User Since: 24th Mar 2009
System Score: N/A
Location: N/A
I am having exactly the same problem. The Toolbox Download Solution and Solution Wizard will not work with Insecure Program Sun Java JRE 1.5.x/5.x
Plus, when I re-scan the program after I have installed the latest version, I still get Insecure Program Sun Java JRE 1.5.x/5.x
Can anyone help, please?
Was this reply relevant?
+0
-0
wr RE: Insecure Program Sun Java JRE 1.5.x/5.x
Contributor 29th Mar, 2009 14:53
Score: 308
Posts: 736
User Since: 30th Mar 2008
System Score: 100%
Location: US
To locate the exact file that the Secunia PSI has detected, please follow there guidelines using the
ADVANCED interface:
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
* Click on the + sign of the program to “expand’ it.
* Click on Technical Details in the Toolbox to see the installation path of the detected file.
* Remember the installation path and close down the menu.
* Click Open Folder and locate the detected file.

Regards,
wr

--
HP Pavilion Slimline s3020n
Windows Vista Home Premium SP2 32 bit
AMD 64 Athlon X2
Firefox 24.4.0 ESR
The weakest link of a computer system is always sitting in front of the monitor.
Was this reply relevant?
+0
-0
HLS RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 29th Mar, 2009 15:56
Score: 0
Posts: 2
User Since: 23rd Jan 2009
System Score: N/A
Location: N/A
on 28th Nov, 2008 01:44, Litisha wrote:
I don't quite understand. Can anyone help me. I read the forum and I uninstalled my Java and reinstalled the updated version. I currently have the most updated version, version 6 update 10. I rescanned my secunia and it still shows the Sun Java JRE 1.5.x/5.x as being still not being patched.

Thank you

Was this reply relevant?
+0
-0
tinojacobsen RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 30th Mar, 2009 09:21
Score: 0
Posts: 2
User Since: 24th Feb 2009
System Score: N/A
Location: N/A
on 28th Nov, 2008 01:44, Litisha wrote:
I don't quite understand. Can anyone help me. I read the forum and I uninstalled my Java and reinstalled the updated version. I currently have the most updated version, version 6 update 10. I rescanned my secunia and it still shows the Sun Java JRE 1.5.x/5.x as being still not being patched.

Thank you

Was this reply relevant?
+0
-0
Direhs RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 30th Mar, 2009 11:11
Score: 0
Posts: 1
User Since: 26th Nov 2008
System Score: N/A
Location: N/A
I'm having a similar problem. I cannot even get the solution to download! I click on "solution" and nothing happens. I'm anxious to hear what responses you get to your question. Maybe it will answer mine as well!
Was this reply relevant?
+0
-0
Poul Hvolbæk RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 30th Mar, 2009 11:16
Score: 0
Posts: 2
User Since: 23rd Mar 2009
System Score: N/A
Location: N/A
on 28th Nov, 2008 08:03, BigDave_39 wrote:
Try looking at the paths where the PSI detected your installation of Java JRE - it may give you an idea to why it is being found.

You can also copy and paste the path into this thread.

Was this reply relevant?
+0
-0
Poul Hvolbæk RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 30th Mar, 2009 11:17
Score: 0
Posts: 2
User Since: 23rd Mar 2009
System Score: N/A
Location: N/A
on 28th Nov, 2008 08:03, BigDave_39 wrote:
Try looking at the paths where the PSI detected your installation of Java JRE - it may give you an idea to why it is being found.

You can also copy and paste the path into this thread.

Was this reply relevant?
+0
-0
Maurice Joyce RE: Insecure Program Sun Java JRE 1.5.x/5.x
Handling Contributor 30th Mar, 2009 11:32
Score: 11720
Posts: 8,956
User Since: 4th Jan 2009
System Score: N/A
Location: UK
There are many threads with solutions to this problem.
I have copied this one here for U:

There is a very interesting thread on this subject here:
http://secunia.com/community/forum/thread/show/776...

I carry out the action outlined below each time I update JAVA - works for me.

Eliminating older versions of JAVA or JRE from your system.

Download the latest Java from here:
http://www.java.com/en/

The next programme will remove all old versions except the one U have just downloaded.

http://raproducts.org/

*This link takes U to the site - select the Windows Binary (zip) option.
*This will lead U to Sourceforge.net to download it.
*Save the download to desktop.
*Activate the desktop zip icon which exposes the JAVARA EXE file. Click it
*Select RUN when asked.
*Select your language.
*The tool will now appear on the desktop - select REMOVE OLDER VERSIONS
*Once complete select ADDITIONAL TASKS - tick all boxes & activate.

This should have completely removed all old versions. To verify this fact
* Go to control panel>add/remove - you should see JAVA(TM)6 Update 13 - there should be NO other references to JAVA or JRE
* Rerun Secunia - U should get a clean bill of health.


* Right click on the desktop JAVARA zip file & delete it.



--
Maurice

Windows 7 SP1 64 Bit OS
HP Intel Pentium i7
IE 11 for Windows 7 SP1
16GB RAM
Was this reply relevant?
+0
-0
This user no longer exists RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 30th Mar, 2009 18:35
on 28th Nov, 2008 01:44, Litisha wrote:
I don't quite understand. Can anyone help me. I read the forum and I uninstalled my Java and reinstalled the updated version. I currently have the most updated version, version 6 update 10. I rescanned my secunia and it still shows the Sun Java JRE 1.5.x/5.x as being still not being patched.

Thank you

Was this reply relevant?
+0
-0
effadj RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 30th Mar, 2009 20:18
Score: 0
Posts: 2
User Since: 8th Dec 2008
System Score: N/A
Location: US
on 30th Mar, 2009 11:11, Direhs wrote:
I'm having a similar problem. I cannot even get the solution to download! I click on "solution" and nothing happens. I'm anxious to hear what responses you get to your question. Maybe it will answer mine as well!
Dido! Any ideas?
Was this reply relevant?
+0
-0
Kurosh RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 30th Mar, 2009 20:37
Score: 3
Posts: 64
User Since: 30th Mar 2009
System Score: N/A
Location: CA
If the "insecure" version that is being detected is in your [drive]:\i386 folder (which is where Windows puts the installation files when it first installs Windows), then you can ignore this warning ... this is not your currently installed version of Java.

I had this same warning, but anything in the \i386 folder can be ignored. I made an ignore rule for that folder.

See this for more information:

http://secunia.com/vulnerability_scanning/personal...

(Q&As 22 to 25 answer this specifically)

Best Wishes,
Kurosh
Was this reply relevant?
+0
-0
tinojacobsen RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 31st Mar, 2009 10:02
Score: 0
Posts: 2
User Since: 24th Feb 2009
System Score: N/A
Location: N/A
on 28th Nov, 2008 01:44, Litisha wrote:
I don't quite understand. Can anyone help me. I read the forum and I uninstalled my Java and reinstalled the updated version. I currently have the most updated version, version 6 update 10. I rescanned my secunia and it still shows the Sun Java JRE 1.5.x/5.x as being still not being patched.

Thank you

Was this reply relevant?
+0
-0
lance_yien RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 31st Mar, 2009 16:09
Score: 0
Posts: 1
User Since: 27th Jan 2009
System Score: N/A
Location: N/A
Last edited on 31st Mar, 2009 16:20
Hello,

on 29th Mar, 2009 13:55, Tinkywinky wrote:
I am having exactly the same problem. The Toolbox Download Solution and Solution Wizard will not work with Insecure Program Sun Java JRE 1.5.x/5.x
Plus, when I re-scan the program after I have installed the latest version, I still get Insecure Program Sun Java JRE 1.5.x/5.x
Can anyone help, please?


No problem with these steps and No needs to run JavaRaz:

- Download, on your Desktop, the newest version (Recommended Version 6 Update 13) from here: http://www.java.com/en/download/manual.jsp (Windows XP/Vista/2000/2003/2008 Offline

- Go to Start => Control Panel double-click on the Software icon => Add or Remove programs.
Search in the list for all previous installed versions of Java (J2SE Runtime Environment.... ).
Select each in turn and click Remove

- Now install the newest version.

- Restart your PC.

- Start PSI and do a new scan.
Was this reply relevant?
+0
-0
GoneToPlaid RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 1st Apr, 2009 01:25
Score: 5
Posts: 71
User Since: 1st Apr 2009
System Score: 100%
Location: Atlanta, US
Last edited on 1st Apr, 2009 01:27
Well, I got to the bottom of this issue of PSI reporting either or both of the following as being insecure programs:

Java 2SE or Java Web Start

This can occur if at one time you had installed older versions of Java or Java2SE, but of course are updated to the latest Java 6 U13. Java 6 installs three important files

java.exe
javaw.exe
javaws.exe

into the System32 directory, but forgets to check and remove any older versions of these three files which which have identical names and which are in the System directory. So, after checking that these three files are present both in your Windows\System and Windows\System32 directories, simply open a command prompt, navigate to your Windows\System directory (not System32!!!), and delete these three files since they are not in use anyway. Only the newer versions in the System32 directory are or may be in use.
Was this reply relevant?
+0
-0
tingvej11 RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 1st Apr, 2009 12:56
Score: 0
Posts: 2
User Since: 31st Mar 2009
System Score: N/A
Location: N/A
on 28th Nov, 2008 01:44, Litisha wrote:
I don't quite understand. Can anyone help me. I read the forum and I uninstalled my Java and reinstalled the updated version. I currently have the most updated version, version 6 update 10. I rescanned my secunia and it still shows the Sun Java JRE 1.5.x/5.x as being still not being patched.

Thank you

Was this reply relevant?
+0
-0
J.Bekkvik RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 9th Apr, 2009 14:49
Score: 0
Posts: 4
User Since: 28th Nov 2008
System Score: N/A
Location: NO
feil
Was this reply relevant?
+0
-0
Grumnall RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 9th Apr, 2009 16:07
Score: 0
Posts: 1
User Since: 26th Dec 2008
System Score: N/A
Location: N/A
Yo Kenny.
Many thanks for this info and link....It worked for me!
Regards
Grumnall
Was this reply relevant?
+0
-0
tingvej11 RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 10th Apr, 2009 12:45
Score: 0
Posts: 2
User Since: 31st Mar 2009
System Score: N/A
Location: N/A
on 28th Nov, 2008 01:44, Litisha wrote:
I don't quite understand. Can anyone help me. I read the forum and I uninstalled my Java and reinstalled the updated version. I currently have the most updated version, version 6 update 10. I rescanned my secunia and it still shows the Sun Java JRE 1.5.x/5.x as being still not being patched.

Thank you

Was this reply relevant?
+0
-0
marcos.cubas RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 12th Apr, 2009 21:00
Score: 0
Posts: 2
User Since: 9th Jan 2009
System Score: N/A
Location: N/A
on 28th Nov, 2008 01:44, Litisha wrote:
I don't quite understand. Can anyone help me. I read the forum and I uninstalled my Java and reinstalled the updated version. I currently have the most updated version, version 6 update 10. I rescanned my secunia and it still shows the Sun Java JRE 1.5.x/5.x as being still not being patched.

Thank you

Was this reply relevant?
+0
-0
This user no longer exists RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 13th Apr, 2009 01:58
Please don't click on Quote without a Reply.
Was this reply relevant?
+0
-0
BJRNEN RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 28th Apr, 2009 20:07
Score: 0
Posts: 1
User Since: 24th Apr 2009
System Score: N/A
Location: N/A
on 28th Nov, 2008 01:44, Litisha wrote:
I don't quite understand. Can anyone help me. I read the forum and I uninstalled my Java and reinstalled the updated version. I currently have the most updated version, version 6 update 10. I rescanned my secunia and it still shows the Sun Java JRE 1.5.x/5.x as being still not being patched.

Thank you

Was this reply relevant?
+0
-0
joker49 RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 11th May, 2009 16:18
Score: 0
Posts: 1
User Since: 6th May 2009
System Score: N/A
Location: N/A
on 28th Nov, 2008 01:44, Litisha wrote:
I don't quite understand. Can anyone help me. I read the forum and I uninstalled my Java and reinstalled the updated version. I currently have the most updated version, version 6 update 10. I rescanned my secunia and it still shows the Sun Java JRE 1.5.x/5.x as being still not being patched.

Thank you

Was this reply relevant?
+0
-0
Fox_Reinhard RE: Insecure Program Sun Java JRE 1.5.x/5.x
Member 16th May, 2009 13:02
Score: 0
Posts: 1
User Since: 16th May 2009
System Score: N/A
Location: N/A
I figured out that the two items are not related to the latest update versions. So, If you have Windows XP you can use uninstallation program, go to system file - go to software (click)
then you will have the list (listed like java IRE 1.5x/5x, updates 4 and 6. Then run the uninstall-program.
A rescan with secunia shows that this worked.
Was this reply relevant?
+0
-0

This thread has been marked as locked.


 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Reports
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2014 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability