Business users "must not ignore" Oracle Java 7 web browser flaws
Security researchers claim business users could ignore advice to disable plug-ins over app stability fears.

Security researchers have urged users to disable internet browser Java plug-ins, despite concerns about the impact it will have on their line-of-business applications.
As reported by IT Pro earlier this week, the US government has urged internet users to switch off Java in their web browsers following the discovery of two Oracle Java 7 zero-day vulnerabilities.
The issue is understood to affect web browsers that use the Java 7 plug-in, including Mozilla Firefox, Google Chrome, Internet Explorer and Apple Safari.
Removing Java from computers eliminates the attack surface, but it will break browser-based apps.
The bugs allow Java applets to carry out arbitrary operating system commands without permission, which could allow vulnerable systems to be infected with malware.
Despite this, IT security experts claim some enterprise users might be tempted to ignore the US government's advice because of the disruption it could cause to their business.
For instance, Ziv Mador, director of security research at Trustwave SpiderLabs, said companies that use browser-based Java apps would experience problems.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"Removing Java from computers eliminates the attack surface, but it is used in line-of-business and consumer applications and will clearly break [them].
"[It] is an issue administrators will need to take into account before they act on this [advice]," he added.
This is a view backed by Rik Ferguson, director of security research at anti-virus vendor Trend Micro, who said this could put some users off disabling Java.
"Some users, depending on who their security vendor is, might feel confident enough in its ability to detect every single variant of malware [this could expose them to], which is, perhaps, not that sensible," said Ferguson.
"There are some workarounds, though, most of which are pretty clunky," he added.
For instance, IT administrations could tell staff to use a different browser, such as Google Chrome, to run their business applications in and another for general internet use.
"It means having two separate browsers and relying on users to maintain that policy for as long as that alert's in place, which is why it's a bit clunky," he explained.
"The simplest solution would be for Oracle to release a patch, especially as this is a vulnerability that is affecting so many different platforms.
Meanwhile, Tal Be'ery, web research team leader at security vendor Imperva, said it is "nearly impossible" for IT administrators to disable a single software component on every machine they are responsible for.
"The current case of disabling Java components is no different," he said.
"Individual users should turn off Java 7 browser plug-ins and only enable them [for] trusted sites, such as [those hosting] Java-powered line of business applications."
Pressure is growing on Oracle to patch the vulnerabilities ahead of its next Java 7 update, which is due in October, following claims that a Polish IT security research team alerted the software giant to the problem back in April.
-
Third time lucky? Microsoft finally begins roll-out of controversial Recall feature
News The Windows Recall feature has been plagued by setbacks and backlash from security professionals
By Emma Woollacott Published
-
The UK government wants quantum technology out of the lab and in the hands of enterprises
News The UK government has unveiled plans to invest £121 million in quantum computing projects in an effort to drive real-world applications and adoption rates.
By Emma Woollacott Published
-
Spanish spyware outfit uncovered, develops exploits for Windows, Chrome, and Firefox
News Google was only able to discover the company after an anonymous submission was made to its Chrome bug reporting programme
By Zach Marzouk Published
-
Google adds new security vendor plugins for Chrome, improved Chrome OS policy controls for IT admins
News New integrations across various security pillars aim to improve Chrome OS and Chrome browser security for enterprise customers
By Connor Jones Published
-
Google patches second Chrome browser zero-day of 2022
News Google acted quickly to secure against the type confusion vulnerability that was under active exploitation
By Connor Jones Published
-
Acer Chromebook Spin 513 review: Cheap and mostly cheerful
Reviews An affordable Chromebook convertible with good looks but mediocre performance
By Mike Jennings Published
-
Google says Chrome is now faster than Safari on Apple Silicon
News According to Apple's own benchmarks, Chrome 99 scored the highest out of any browser ever tested
By Connor Jones Published
-
Google Chrome update fixes zero-day under active exploitation
News Google releases a fresh wave of patches for severe vulnerabilities that could facilitate code execution and system takeover via Google Chrome
By Connor Jones Published
-
Asus Chromebook CX9 (CX9400CE) review: The most stylish Chromebook on the market
Reviews A sleek, expensive Chromebook that tries to bring professional style to Google’s OS
By Mike Jennings Published
-
Firefox 95 boosts protection against zero-day attacks
News Mozilla's browser now takes a more granular approach to walling off code
By Danny Bradbury Published