EDR: Can Java be updated if my current version has vulnerabilities?
search cancel

EDR: Can Java be updated if my current version has vulnerabilities?

book

Article ID: 287978

calendar_today

Updated On:

Products

Carbon Black EDR (formerly Cb Response)

Issue/Introduction

Can Java be updated if my current version has vulnerabilities?

Environment

  • Carbon Black EDR: All Versions
  • Java OpenJDK

Resolution

OpenJDK can be upgraded within the minor build version but this should only be done as a last option. If you are not on the latest version of the on-prem EDR Server, upgrade that first and verify the current version is outside the vulnerability. 

Additional Information

Although we do not foresee issues with upgrading Java OpenJDK, this is done at your own risk. QA testing is done on the version shipped with each CB EDR Server version only. VMWare CB does not install the Java JDK, so we recommend following the guidelines provided by the OS provider.