JRun weaknesses in the 9.0.1 Updater?
As part of our insurance, we're required to pass tests from SecurityMetrics.com that evaluate the security of our website. We've passed the last several tests, but our most recent test failed yesterday. The only major change we've made in the intervening time has been to run the 9.0.1 updater.
Our system is Windows 2008 64-bit with the 9.0.1 Updater and cumulative hotfix applied.
The error we're receiving is this:
"JRun JSESSIONID weakness Severity Several vulnerabilities in JRun server could allow an intruder to view arbitrary files, execute arbitrary code, or list directories on the server."
As a solution it points me to abobe security fixes from 3 years ago which talk mostly about MX7 and 8 and tell me to run the JRun Updater 7.
So my question to everyone is what should I do about this? Did Adobe update JRun in the updater and re-introduce some security holes it had previously fixed? Should I roll back to a previous version of JRun? And how would I do that?
