• Inviting everyone who uses WordPress management tools in Plesk
    The Plesk team is conducting a 60-minute research session that includes an interview and a moderated usability test.
    To participate, please use this link .
    Your experience will help shape product decisions and ensure the tools better support real-world use cases.

Question jvm on plesk Obsidian (log4j exploit)

SalvadorS

Regular Pleskian
Hello,

I have a debian server with Plesk Obsidian and I found a folder:


/usr/lib/jvm


lrwxrwxrwx 1 root root 24 may 6 2014 default-java -> java-1.7.0-openjdk-amd64
lrwxrwxrwx 1 root root 20 may 19 2017 java-1.7.0-openjdk-amd64 -> java-7-openjdk-amd64
drwxr-xr-x 5 root root 4096 ago 3 2017 java-7-openjdk-amd64
drwxr-xr-x 8 root root 4096 ene 3 2018 java-8-oracle
drwxr-xr-x 9 root root 4096 ago 3 2017 jdk-8-oracle-x64
drwxr-xr-x 7 root root 4096 ago 3 2017 jre-8-oracle-x64

I don´t know why is that there as I don´t use java, tomcat, servlets...

Thinking in log4j exploit, how can i delete this? delete the folder and thats all?
 
Plesk does not use Java internally, so Plesk is not affected by this vulnerability. Since Tomcat support in Plesk was dropped in Plesk 17.8, Plesk does not support users' Java-based applications.

I think you have to remove all java related packages on OS level.
 
Back
Top