Oracle JDK 7 (LTS)
Oracle JDK 7 (LTS)
The Oracle OS Oracle JDK 7 (LTS) reached end of service life on Jul 19, 2022 — Oracle OS no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
24/7 engineers own your Oracle JDK 7 (LTS) incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- oracle-jdk
- release
- 7
- product Label
- Oracle JDK
- release Label
- 7 (LTS)
- codename
- lts
- true
- latest Version
- 7u351
- release Date
- 2011-07-11
- maintained
- source Url
- https://endoflife.date/oracle-jdk
Lifecycle Dates
- End of Service Life
- Jul 19, 2022
- Last OEM Support
- Jul 31, 2019
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Oracle JDK 7 (LTS) — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Oracle JDK 7 (LTS)?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Oracle JDK 7 (LTS) when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Oracle JDK 7 (LTS) Support: Frequently Asked Questions
Is the Oracle OS Oracle JDK 7 (LTS) still supported?
Oracle OS ended support for the Oracle JDK 7 (LTS) on Jul 19, 2022 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the Oracle OS Oracle JDK 7 (LTS) end of service life (EOSL) date?
Oracle OS lists the end of service life for the Oracle JDK 7 (LTS) as Jul 19, 2022.
Can I keep using the Oracle JDK 7 (LTS) after its EOSL date?
Yes. EOSL means Oracle OS stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Oracle JDK 7 (LTS) cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Oracle JDK 7 (LTS)
2 published CVEs affect the Oracle OS Oracle JDK 7 (LTS), including 2 rated critical or high severity. Oracle OS no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2022-21476 | HIGH | 7.5 | Apr 19, 2022 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can resul |
| CVE-2012-4420 | HIGH | 7.5 | Dec 26, 2019 | An information disclosure flaw was found in the way the Java Virtual Machine (JVM) implementation of Java SE 7 as provided by OpenJDK 7 incorrectly initialized integer arrays after memory allocation (in certain circumstances they had nonzero elements right after the allocation). A remote attacker could use this flaw to obtain potentially sensitive information. |