Source | Azure Portal | ||||||||||||||
Display name | [Deprecated]: Ensure that 'Java version' is the latest, if used as a part of the API app | ||||||||||||||
Id | 88999f4c-376a-45c8-bcb3-4058f713cf39 | ||||||||||||||
Version | 2.0.0-deprecated Details on versioning |
||||||||||||||
Versioning |
Versions supported for Versioning: 1 2.0.0 (2.0.0-deprecated) Built-in Versioning [Preview] |
||||||||||||||
Category | App Service Microsoft Learn |
||||||||||||||
Description | Periodically, newer versions are released for Java either due to security flaws or to include additional functionality. Using the latest Python version for API apps is recommended in order to take advantage of security fixes, if any, and/or new functionalities of the latest version. We recommend all customers who are still using API apps to implement the built-in policy called 'App Service apps that use Java should use the latest 'Java version'', which is scoped to include API apps in addition to Web apps. | ||||||||||||||
Cloud environments | AzureCloud = true AzureUSGovernment = unknown AzureChinaCloud = unknown |
||||||||||||||
Available in AzUSGov | Unknown, no evidence if Policy definition is/not available in AzureUSGovernment | ||||||||||||||
Assessment(s) |
Assessments count: 1 Assessment Id: 08a3b009-0178-ee60-e357-e7ee5aea59c7 DisplayName: Java should be updated to the latest version for API apps Description: It's important to regularly update Java for API apps to the latest version. New versions often include security fixes for identified vulnerabilities and may also introduce additional functionality. If Java is not updated, the API apps could be exposed to security risks due to potential flaws in older versions. Additionally, they may miss out on the benefits of new features and improvements offered in the latest versions. Remediation description: To set the latest Java version for your API app: 1. Navigate to Azure App Service 2. Go to Configuration 3. Select the latest Java version in the JVM drop down. For more information, visit here: https://aka.ms/configure-java Categories: AppServices Severity: Medium preview: True |
||||||||||||||
Mode | Indexed | ||||||||||||||
Type | BuiltIn | ||||||||||||||
Preview | False | ||||||||||||||
Deprecated | True | ||||||||||||||
Effect | Default AuditIfNotExists Allowed AuditIfNotExists, Disabled |
||||||||||||||
RBAC role(s) | none | ||||||||||||||
Rule aliases | THEN-ExistenceCondition (1)
|
||||||||||||||
Rule resource types | IF (1) |
||||||||||||||
Compliance | Not a Compliance control | ||||||||||||||
Initiatives usage | none | ||||||||||||||
History |
|
||||||||||||||
JSON compare |
compare mode:
version left:
version right:
|
||||||||||||||
JSON |
|