Hi there,
We recently completed an upgrade of our production environment to JIRA 5.1.5. One of our security analysts has run a vulnerability scan on our new server and has identified a risk due to older an version of java runtime (5.1.5 is bundled with jre version 1.6.0_26) He would like for us to upgrade the jre to 6 update 37 to address various security issues.
Can you please advise what risk does this involve? Would you recommend rigorous testing for this type of change to our JIRA environment?
If we are running JIRA as a windows service do we just need to point the relevant key in the registry to the new jvm.dll or is extra configuration required?
eg:
Windows Registry Editor Version 5.00
HKEY_LOCAL_MACHINE SOFTWARE Wow6432Node Apache Software Foundation Procrun 2.0 JIRA Parameters Java
Jvm=D: Atlassian JIRA jre bin server jvm.dll
Thanks,
Ben