Issue
I/A Series R2 and G3 Security Update - Oracle has released a Critical Patch Update for Java SE that addresses a number of security vulnerabilities
Environment
I/A Series R2 - All versions
I/A Series G3 - All versions
Cause
Oracle has released a Critical Patch Update for Java SE that addresses a number of security vulnerabilities. The patch contains fixes for 50 security vulnerabilities including 44 that only affect client deployment of Java. These vulnerabilities can only be exploited on desktops through Java Web Start applications or Java applets. One reported vulnerability exploits the installation process of client deployment of Java – installation of the Java Runtime Environment on desktops. This Critical Patch Update also includes fixes that were previously released with the Java 7 Update 11 alert (Security Alert CVE-2013-0422).
Resolution
Download and review TPA-IA-13-0001.01 Technical Product Advisory that details the vulnerabilities. Schneider Electric recommends that customers evaluate the risk of enabling Java, based on how the affected PC is used and that customers review the download and install the Critical Patch Update as needed.