<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Java vulnerability for 1.7.10 and below in Java Maps SDK Questions</title>
    <link>https://community.esri.com/t5/java-maps-sdk-questions/java-vulnerability-for-1-7-10-and-below/m-p/560480#M1763</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;One of my developers believes that Java 6 is embedded in the ArcGIS software.&amp;nbsp; I've not heard that, before.&amp;nbsp; So, I thought I would come to the source to find out the truth of it all.&amp;nbsp; Has anyone heard that?&amp;nbsp; I am attempting to verify the vulnerabilities pertaining to Java 6, since it has not been supported for some time.&amp;nbsp; Please let me know if this is accurate.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Dec 2013 18:08:15 GMT</pubDate>
    <dc:creator>KenSanders</dc:creator>
    <dc:date>2013-12-18T18:08:15Z</dc:date>
    <item>
      <title>Java vulnerability for 1.7.10 and below</title>
      <link>https://community.esri.com/t5/java-maps-sdk-questions/java-vulnerability-for-1-7-10-and-below/m-p/560477#M1760</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;A new critical vulnerability has been discovered in Java 1.7.x, and the Federal Goverment has mandated the removal of all versions of Java 1.7.10 and earlier, and the installation of 1.7.11 to circumvent this issue. The latest ArcGIS Runtime for Java 10.1.1 only supports Java Development Kits 6 update 37 through 7 update 9. Since the latest version of ArcGIS Runtime for Java just got released, what is ESRI's resolution?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I've personally tested the installation and ran most samples provided with no seamingly known misbehavior against JRE 1.7.11, but my test is obviously not all-inclusive.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Carlos&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jan 2013 09:34:29 GMT</pubDate>
      <guid>https://community.esri.com/t5/java-maps-sdk-questions/java-vulnerability-for-1-7-10-and-below/m-p/560477#M1760</guid>
      <dc:creator>CarlosColón-Maldonado</dc:creator>
      <dc:date>2013-01-22T09:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: Java vulnerability for 1.7.10 and below</title>
      <link>https://community.esri.com/t5/java-maps-sdk-questions/java-vulnerability-for-1-7-10-and-below/m-p/560478#M1761</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;The statement "supports Java Development Kits 6 update 37 through 7 update 9" should probably be reworded slightly.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;To explain why we state these JRE/ JDK versions, when we test a new release we take the latest available versions of Java 6 and 7 and certify against those versions.&amp;nbsp; 10.1.1 was certified against 6u37 and 7u9.&amp;nbsp; These were the most up to date versions at the time we were testing late last year.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;New releases of Java come out all the time to fix bugs and plug security holes and theoreticaly this should not cause a problem with the Runtime.&amp;nbsp; I can't however guarantee that a new Java bug or security issue has been introduced in their latest release which may affect Runtime functionality.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I'm also using 7u11 and so far I've not seen any issues.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I hope this helps.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Mark&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jan 2013 09:27:48 GMT</pubDate>
      <guid>https://community.esri.com/t5/java-maps-sdk-questions/java-vulnerability-for-1-7-10-and-below/m-p/560478#M1761</guid>
      <dc:creator>MarkBaird</dc:creator>
      <dc:date>2013-01-23T09:27:48Z</dc:date>
    </item>
    <item>
      <title>Re: Java vulnerability for 1.7.10 and below</title>
      <link>https://community.esri.com/t5/java-maps-sdk-questions/java-vulnerability-for-1-7-10-and-below/m-p/560479#M1762</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Thanks for replying, Mark.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;While aware of any Java-supported vendor's inability to guarantee compatibility with future JRE updates, as a customer, I would think that support of any potential software issues with them ought to be granted by the vendor. While it has not being my experience so far in the case with ESRI, I merely wanted to confirm the software requirements statement.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I'm glad to see the effort made to ensure JRE compliance and compatibility.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jan 2013 11:54:48 GMT</pubDate>
      <guid>https://community.esri.com/t5/java-maps-sdk-questions/java-vulnerability-for-1-7-10-and-below/m-p/560479#M1762</guid>
      <dc:creator>CarlosColón-Maldonado</dc:creator>
      <dc:date>2013-01-23T11:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: Java vulnerability for 1.7.10 and below</title>
      <link>https://community.esri.com/t5/java-maps-sdk-questions/java-vulnerability-for-1-7-10-and-below/m-p/560480#M1763</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;One of my developers believes that Java 6 is embedded in the ArcGIS software.&amp;nbsp; I've not heard that, before.&amp;nbsp; So, I thought I would come to the source to find out the truth of it all.&amp;nbsp; Has anyone heard that?&amp;nbsp; I am attempting to verify the vulnerabilities pertaining to Java 6, since it has not been supported for some time.&amp;nbsp; Please let me know if this is accurate.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Dec 2013 18:08:15 GMT</pubDate>
      <guid>https://community.esri.com/t5/java-maps-sdk-questions/java-vulnerability-for-1-7-10-and-below/m-p/560480#M1763</guid>
      <dc:creator>KenSanders</dc:creator>
      <dc:date>2013-12-18T18:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: Java vulnerability for 1.7.10 and below</title>
      <link>https://community.esri.com/t5/java-maps-sdk-questions/java-vulnerability-for-1-7-10-and-below/m-p/560481#M1764</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I have not noticed the embedding of an earlier Java Runtime Environment libraries on any of all Runtime installations (though it seems strange that Java is not listed as required software in the system &lt;/SPAN&gt;&lt;A href="https://developers.arcgis.com/en/java/info/arcgis-runtime-sdk-for-java-system-requirements.htm"&gt;requirements for 10.2&lt;/A&gt;&lt;SPAN&gt;). An easy way to test that theory is to remove all Java deployments from the box to see if the samples will work, but I doubt it. I am using ONLY Java version 1.7.0.17-b02 and have no issues with it.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Dec 2013 19:06:35 GMT</pubDate>
      <guid>https://community.esri.com/t5/java-maps-sdk-questions/java-vulnerability-for-1-7-10-and-below/m-p/560481#M1764</guid>
      <dc:creator>CarlosColón-Maldonado</dc:creator>
      <dc:date>2013-12-18T19:06:35Z</dc:date>
    </item>
    <item>
      <title>Re: Java vulnerability for 1.7.10 and below</title>
      <link>https://community.esri.com/t5/java-maps-sdk-questions/java-vulnerability-for-1-7-10-and-below/m-p/560482#M1765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;The jar files in the ArcGISRuntime are compiled against 6u45.&amp;nbsp; This is how we can support Java 6 and Java 7.&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Our plan is to support Java 6 for one more version (which is due to be released early next year).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;After that the product will be compiled using Java 7 and we will support Java 8 (if it is released).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Mark&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Dec 2013 07:17:12 GMT</pubDate>
      <guid>https://community.esri.com/t5/java-maps-sdk-questions/java-vulnerability-for-1-7-10-and-below/m-p/560482#M1765</guid>
      <dc:creator>MarkBaird</dc:creator>
      <dc:date>2013-12-19T07:17:12Z</dc:date>
    </item>
  </channel>
</rss>

