• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Question jvm on plesk Obsidian (log4j exploit)

SalvadorS

Regular Pleskian
Hello,

I have a debian server with Plesk Obsidian and I found a folder:


/usr/lib/jvm


lrwxrwxrwx 1 root root 24 may 6 2014 default-java -> java-1.7.0-openjdk-amd64
lrwxrwxrwx 1 root root 20 may 19 2017 java-1.7.0-openjdk-amd64 -> java-7-openjdk-amd64
drwxr-xr-x 5 root root 4096 ago 3 2017 java-7-openjdk-amd64
drwxr-xr-x 8 root root 4096 ene 3 2018 java-8-oracle
drwxr-xr-x 9 root root 4096 ago 3 2017 jdk-8-oracle-x64
drwxr-xr-x 7 root root 4096 ago 3 2017 jre-8-oracle-x64

I don´t know why is that there as I don´t use java, tomcat, servlets...

Thinking in log4j exploit, how can i delete this? delete the folder and thats all?
 
Plesk does not use Java internally, so Plesk is not affected by this vulnerability. Since Tomcat support in Plesk was dropped in Plesk 17.8, Plesk does not support users' Java-based applications.

I think you have to remove all java related packages on OS level.
 
Back
Top