JRE - Security Threat on browsers
Recently, JRE and Java apps running on browsers are considered to be potential security threats. In Firefox, it is deactive by default. Why suddenly Java is considered to be security threat? Although, nowadays we don't use applets for most of the browser applications (Rules round-up on Javaranch could be an exception ).
Is this security vulnerability applicable to server side applications running on Java?
Thanks for sharing your thoughts on this.
On the subject you might find this podcast transcript interesting.
It talks the issue you mention. Search for 'So there are unpatched
problems' if you don't want to read the whole thing.
What's changed is the mindset of people (certainly heightened recently by all the talk about what the NSA is up to), and -in client-side Java's case- a sense that it is outdated technology, and so accepting the security weaknesses no longer outweighs the benefits of using it.
The recent Java exploits are a different breed entirely, in that they relied on 'pure Java'. They had nothing to do with C. Many of them were discovered 18 months ago by Security Explorations. They allowed Java applets to escape the Java sandbox, and run with the same privileges as your web browser.
Server side applications are a complex story...it depends on the framework you are using. Servlets running under programs like Apache Tomcat are vulnerable, as Tomcat uses Java's security sandbox to protect itself from malicious servlets. So today a malicious servlet could crash Tomcat, or, worse, corrupt how it runs.
But other frameworks that don't use Java's SecurityManager are not vulnerable to these recent exploits.