Brand Logo
Help
  • Get started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Login / Register
Help
  • Get started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
close
  • Community Home
  • Forums
    • By Topic
    • By Topic
      EcoStruxure Building
      • Field Devices Forum
      • SmartConnector Forum
      EcoStruxure Power & Grid
      • Gateways and Energy Servers
      • Metering & Power Quality
      APC UPS, Critical Power, Cooling and Racks
      • APC UPS Data Center & Enterprise Solutions Forum
      • APC UPS for Home and Office Forum
      EcoStruxure IT
      • EcoStruxure IT forum
      Remote Operations
      • EcoStruxure Geo SCADA Expert Forum
      • Remote Operations Forum
      Industrial Automation
      • Alliance System Integrators Forum
      • AVEVA Plant SCADA Forum
      • CPG Expert Forum DACH
      • EcoStruxure Automation Expert / IEC 61499 Forum
      • Fabrika ve Makina Otomasyonu Çözümleri
      • Harmony Control Customization Forum
      • Industrial Edge Computing Forum
      • Industry Automation and Control Forum
      • Korea Industrial Automation Forum
      • Machine Automation Forum
      • Modicon PAC Forum
      • PLC Club Indonesia
      Schneider Electric Wiser
      • Schneider Electric Wiser Forum
      Power Distribution IEC
      • Eldistribution & Fastighetsautomation
      • Elektrik Tasarım Dağıtım ve Uygulama Çözümleri
      • Paneelbouw & Energie Distributie
      • Power Distribution and Digital
      • Solutions for Motor Management
      • Specifiers Club ZA Forum
      • Електропроектанти България
      Power Distribution NEMA
      • Power Monitoring and Energy Automation NAM
      Power Distribution Software
      • EcoStruxure Power Design Forum
      • LayoutFAST User Group Forum
      Light and Room Control
      • SpaceLogic C-Bus Forum
      Solutions for your Business
      • Solutions for your Business Forum
      Support
      • Ask the Community
  • Knowledge Center
    • Building Automation Knowledge Base
    • Geo SCADA Knowledge Base
    • Industrial Automation How-to videos
    • Digital E-books
    • Success Stories Corner
  • Events & Webinars
    • All Events
    • Innovation Talks
    • Innovation Summit
    • Let's Exchange Series
    • Partner Success
    • Process Automation Talks
    • Technology Partners
  • Ideas
    • EcoStruxure Building
      • EcoStruxure Building Advisor Ideas
      Remote Operations
      • EcoStruxure Geo SCADA Expert Ideas
      • Remote Operations Devices Ideas
      Industrial Automation
      • Modicon Ideas & new features
  • Blogs
    • By Topic
    • By Topic
      EcoStruxure Power & Grid
      • Backstage Access Resources
      Remote Operations
      • Remote Operations Blog
      Industrial Automation
      • Industrie du Futur France
      • Industry 4.0 Blog
      Power Distribution NEMA
      • NEMA Power Foundations Blog
      Light and Room Control
      • KNX Blog
      Knowledge Center
      • Digital E-books
      • Geo SCADA Knowledge Base
      • Industrial Automation How-to videos
      • Success Stories Corner

Java issues, AGAIN

APC UPS Data Center & Enterprise Solutions Forum

Schneider Electric support forum for our Data Center and Business Power UPS, UPS Accessories, Software, Services, and associated commercial products designed to share knowledge, installation, and configuration.

cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • Home
  • Communities
  • APC UPS, Critical Power, Cooling and Racks
  • APC UPS Data Center & Enterprise Solutions Forum
  • Java issues, AGAIN
Options
  • Subscribe to RSS Feed
  • Mark Topic as New
  • Mark Topic as Read
  • Float this Topic for Current User
  • Bookmark
  • Subscribe
  • Mute
  • Printer Friendly Page
Invite a Co-worker
Send a co-worker an invite to the Exchange portal.Just enter their email address and we’ll connect them to register. After joining, they will belong to the same company.
You have entered an invalid email address. Please re-enter the email address.
This co-worker has already been invited to the Exchange portal. Please invite another co-worker.
Please enter email address
Send Invite Cancel
Invitation Sent
Your invitation was sent.Thanks for sharing Exchange with your co-worker.
Send New Invite Close
Top Experts
User Count
BillP
Administrator BillP Administrator
5022
voidstar_apc
Janeway voidstar_apc
195
Erasmus_apc
Sisko Erasmus_apc
111
TheNotoriousKMP_apc
Sisko TheNotoriousKMP_apc
108
View All
Invite a Colleague

Found this content useful? Share it with a Colleague!

Invite a Colleague Invite
Solved Go to Solution
Back to APC UPS Data Center & Enterprise Solutions Forum
Solved
jhvance_apc
Ensign jhvance_apc
Ensign

Posted: ‎2021-07-01 01:29 AM

0 Likes
3
261
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content
Share

Posted: ‎2021-07-01 01:29 AM

Java issues, AGAIN

This was originally posted on APC forums on 9/3/2012


Okay, the PCBE reliance on Java is getting really old and tiresome, even with the JRE configuration applet made available to modify after-the-fact the rather ancient version (v6 update 19) which is installed each and every time PCBE must be fully uninstalled and then reinstalled again in order to update Java whenever Sun/Oracle releases a new version. When PCBE was initially released years ago and even when the v9.0.1 update was provided in 2011, Java was not the malware vector it has become over the past year as flaws are discovered and now exploited in the wild long before Sun/Oracle gets around to their longstanding quarterly patch schedule.

One of those was in July, but under a rather serious emergency circumstance to address a flaw they had been notified of in April but now being widely exploited. an out-of-schedule update (to v7 update 7) was quietly released late last week after numerous credible security research experts not only provided warnings of the flaw (and its increasing spread through poisoned website code as they were taken over by various miscreants), but who also strongly and repeatedly encouraged users to at least disable it in their browsers if not simply uninstall it completely from their systems.

I've got one Windows Vista Ultimate 32-bit machine which is supported by an aging but still functional APC SU1400 running PCBE, and I've consistently had problems in getting this update do-si-do to resolve and function properly, but normally after a few cycles of uninstalling and reinstalling everything it will somehow sort out whatever issues there are and settle into a configuration that consistently works over repeated boot cycles. However, for the past few days I've repeatedly uninstalled the PCBE Console/Server/Agent and Java, rebooted that machine (and the entire network) and reinstalled in the reverse sequence (i.e., Agent/Server/Console) before running the JRE configuration applet that switches PCBE to use the new updated v7u7 version and delete the ancient v6u19 version. In each cycle, regardless of whether I install the new Java before or wait until after the Agent/Server/Console reinstallation sequence, everything works fine with the old Java version up to the point where that JRE re-configuration step breaks the communications link between Server and Agent which had previously been successfully established and consistently recognized.

I can generally see the console information by using a browser to alternatively login via http://127.0.0.1:3052, but not by going directly into the console application -- it doesn't successfully recognize the node or has the capability to successfully "add" it to the list if I make the manual attempt. To say it's frustrating and an serious waste of my time is an understatement. It is simply NOT a realistic or viable option to recommend that users retain the old and flawed version of Java in order to make their APC product functional!

So, here are a couple of impertinent questions:

1. Why does the JRE reconfiguration tool appear to successfully change the JRE version but break that Server-Agent communications link and then not allow me to re-establish it properly again through the Console, and what else can I try that might work around this issue? Is it something in this new Java 7u7 version?

2. Why won't APC simply recompile the PCBE installer file that incorporates each newly-released and updated version of Java, even if the base PCBE version installed remains at v9.0.1?

I've spent way too much time futzing with this thing -- to the point where I'm really so disenchanted and disinclined it's unlikely to ever want to consider another APC product.

Labels
  • Labels:
  • UPS Management Devices & PowerChute Software
Reply
Share
  • All forum topics
  • Previous Topic
  • Next Topic

Accepted Solutions
voidstar_apc
Janeway voidstar_apc
Janeway

Posted: ‎2021-07-01 01:29 AM

0 Likes
0
260
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content
Share

Posted: ‎2021-07-01 01:29 AM

This was originally posted on APC forums on 9/5/2012


Hey Jim,

These appear to be vulnerabilities with Java-in-the-web-browser (as the Registrar article nicely calls it). The JVM installed with PCBE is only used to run PCBE so it shouldn't be vulnerable. Is there something I'm missing?

Just to make sure the PCBE developers didn't install a copy of Java capable of running in the browser, I did two tests inside a VirtualBox VM (Oracle... the irony, I know):
- Does the private JVM installed with PCBE on a machine WITHOUT Java run code in a browser?
- Does the private JVM installed with PCBE on a machine WITH Java run code in a browser?

Results:
- PCBE (w/ private JVM), no public JVM => Attempt to load an applet in my browser shows a broken plugin icon
- PCBE (w/ private JVM), Oracle v7 JVM => Applet loads using Oracle v7 JVM. Also, PCBE's JVM is not listed in the Java control panel.

So it seems to me like PCBE's private JVM may be old but it is not an exposed attack surface.

I also tried using the JRE reconfiguration tool to see if I could replicate the communication problem you had. The JRE reconfiguration tool didn't work at all for me, even after a restart, though it nicely rolled back its changes. I'd look for a firewall issue here.

See Answer In Context

Reply
Share
Replies 3
jhvance_apc
Ensign jhvance_apc
Ensign

Posted: ‎2021-07-01 01:29 AM

0 Likes
0
260
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content
Share

Posted: ‎2021-07-01 01:29 AM

This was originally posted on APC forums on 9/4/2012


If anyone at APC needs more clarity on the risk which these latest Java exploits pose to users of PCBE who haven't been able to keep its version of Java updated without disabling the UPS Console software functionality, here are just a few links to underscore and emphasize the threat:

Symantec: Criminals Quickly Adopt Java 0-Day Exploit
http://www.eweek.com/c/a/Security/Symantec-Criminals-Quickly-Adopt-Java-0Day-Exploit-584776/

Oracle Java Patch Has Security Flaw, Researchers Say
http://www.eweek.com/c/a/Security/Oracle-Java-Patch-Has-Security-Flaw-Researchers-Say-752035/

Thanks ever so much Java, for that biz-wide rootkit infection
http://www.theregister.co.uk/2012/09/03/java_cleanup/

Reply
Share
BillP
Administrator BillP Administrator
Administrator

Posted: ‎2021-07-01 01:29 AM

0 Likes
0
260
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content
Share

Posted: ‎2021-07-01 01:29 AM

This reply was originally posted by Angela on APC forums on 9/4/2012


hello, thanks for the feedback. i sent this post off to the PCBE team to review your comments. here is what i can tell you know based on some feedback from the PCBE support team.

if you don't want to deal with the java based software, apcupsd might be a good alternative if you have not looked into it. it is third party software but works well and supports many operating systems.

java version 7, update 7 has not been tested but i can at least pass the feedback along on the justification for it since it is not under my umbrella of support. we can also accept the feedback on the patched versions.

Reply
Share
voidstar_apc
Janeway voidstar_apc
Janeway

Posted: ‎2021-07-01 01:29 AM

0 Likes
0
261
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content
Share

Posted: ‎2021-07-01 01:29 AM

This was originally posted on APC forums on 9/5/2012


Hey Jim,

These appear to be vulnerabilities with Java-in-the-web-browser (as the Registrar article nicely calls it). The JVM installed with PCBE is only used to run PCBE so it shouldn't be vulnerable. Is there something I'm missing?

Just to make sure the PCBE developers didn't install a copy of Java capable of running in the browser, I did two tests inside a VirtualBox VM (Oracle... the irony, I know):
- Does the private JVM installed with PCBE on a machine WITHOUT Java run code in a browser?
- Does the private JVM installed with PCBE on a machine WITH Java run code in a browser?

Results:
- PCBE (w/ private JVM), no public JVM => Attempt to load an applet in my browser shows a broken plugin icon
- PCBE (w/ private JVM), Oracle v7 JVM => Applet loads using Oracle v7 JVM. Also, PCBE's JVM is not listed in the Java control panel.

So it seems to me like PCBE's private JVM may be old but it is not an exposed attack surface.

I also tried using the JRE reconfiguration tool to see if I could replicate the communication problem you had. The JRE reconfiguration tool didn't work at all for me, even after a restart, though it nicely rolled back its changes. I'd look for a firewall issue here.

Reply
Share
Preview Exit Preview

never-displayed

You must be signed in to add attachments

never-displayed

Additional options
You do not have permission to remove this product association.
 
To The Top!

Forums

  • APC UPS Data Center Backup Solutions
  • EcoStruxure IT
  • EcoStruxure Geo SCADA Expert
  • Metering & Power Quality
  • Schneider Electric Wiser

Knowledge Center

Events & webinars

Ideas

Blogs

Get Started

  • Ask the Community
  • Community Guidelines
  • Community User Guide
  • How-To & Best Practice
  • Experts Leaderboard
  • Contact Support
Brand-Logo
Subscribing is a smart move!
You can subscribe to this forum after you log in or create your free account.
Forum-Icon

Create your free account or log in to subscribe to the forum - and gain access to more than 10,000+ support articles along with insights from experts and peers.

Register today for FREE

Register Now

Already have an account?Login

Terms & Conditions Privacy Notice Change your Cookie Settings © 2023 Schneider Electric, Inc