Vulnerablity Reported for Java and RHEL

Below vulnerabilities reported for Pega environments on Linux servers.

Oracle Java SE Critical Patch Update - October 2021 (CPUOCT2021)
Red Hat Update for firefox (RHSA-2022:0514)

Can you please confirm the remediation for applying patches will work or if there is anything else we need to perform on the servers?

We got below recommendation from vendors:

Oracle Critical Patch Update Advisory - October 2021
https://www.oracle.com/security-alerts/cpuoct2021.html

https://access.redhat.com/errata/RHSA-2022:0514

Is there any impact of above vulnerabilities on Pega applications?

Pega versions 8.4,7.1.9 and others.

I can provide more details on versions

@ShivaU81

I am unable to open the Oracle-specific URL as this requires an Oracle account.

However, the Patch Updates you are discussing appear to be relevant for your database and OS. As long as you continue using a supported platform stack as per the Platform Support Guide then I see no issue.

Please see our Platform support guide:

“Pegasystems encourages our clients to keep as current as possible with Pega products and with stack components.”

In general, stack component vendors manage forward and backward compatibility very effectively. This means that most of the time, the Pega Platform will continue to operate correctly when stack components are upgraded to new patch levels or versions. Clients are encouraged to upgrade stack components in accord with their IT or business policies, and report any issues via My Support Portal on the Pega Community

@ShivaU81 As @MarijeSchillern mentioned, keeping Java SE updated for critical security updates should be fine to do regularly.

Also consider uninstalling Firefox from your servers, if you don’t need it. Sometimes it’s installed with the OS and not really needed or used, & in those situations I would consider an uninstall instead of upgrading regularly.