Most of the products tested (except Windows Server 2012), use Oracle's Java in one form or another, at least for client access and also in some cases within the management interface. With numerous vulnerabilities recently discovered in Java, leading to guidance from Department of Homeland Security and others to disable it entirely, this raised some questions about usability and possibly even security of the devices tested.
We asked each vendor participating in the review to address the impact of Java as it relates to the products supplied to us for testing, together with guidance for users.
[RELATED: Cisco edges F5 in VPN shootout
-- WatchGuard said that the SSL 560 appliance is not vulnerable to the Oracle Java 7 Security Manager Bypass Vulnerability outlined in US-CERT Alert TA13-010A; however, client systems that utilize the Java-based Access Client feature could be vulnerable if they are running Java 7 Update 10 or lower. The vendor recommends updating to Java 7 Update 11 or later. Clients using Internet Explorer can disable Java and use the ActiveX client loader instead.
-- According to Barracuda Networks, the Java exploit described in the US-CERT does not directly affect the Barracuda SSL VPN. All sessions are self-contained and users are not exposed to external links, scripts or redirection without the administrator explicitly adding the resource. Consequently clients are not exposed to "drive-by-download" or other social engineering risks within the SSL VPN context. The vendor recommends using the latest Java update on client machines and disabling Java execution from the browser when not needed.
-- Dell says while some access methods leverage Java technology for proxy based browser access, there are alternative access methods like Connect Tunnel, Mobile Connect or proxy based browser access using ActiveX. The vendor recommends that administrators determine if Java is appropriate for a specific deployment.
-- F5 says the BIG-IP Edge Gateway 3900 is not affected by CVE-2013-0422 as this vulnerability applies specifically to un-trusted code and BIG-IP doesn't allow code from other sources to be run on the platform. In addition, BIG-IP uses Java 1.6 and, according to F5, the vulnerability only affects Java 1.7.
-- Cisco indicated there is some impact on endpoint advanced functionality, especially if users decide to disable Java as a result of the CVE-2013-0422 alert. The main components relying on Java are the ASDM configuration software and Web launch/Web Deploy of the AnyConnect client. The latter can be circumvented by using pre-deployment of AnyConnect.
Dell this week extended its arsenal of data center Ethernet switches, highlighted by a 100G device with...
For the first time in company history Amazon.com revealed the financial details of its Web Services...
With all the public cloud storage offerings on the market today, many vendors just want customers to...
Sponsored by Broadview Networks
Sponsored by HP
Living up to John McAdam's legacy as F5 Networks' CEO won't be easy, but Manny Rivelo just might be the...
Most Linux kernel code isn’t developed by who you might think. Here’s a closer look at why this matters.
Project Fi, Google's Wi-Fi and cellular network service, can be described as low-cost, disruptive,...
From the 19th century's first designs to the Tesla models we haven't even seen yet, here's the...