Oracle JDK 8 (LTS)
Oracle JDK 8 (LTS)
Third-party support for the Oracle OS Oracle JDK 8 (LTS): 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance — independent of the vendor contract.
24/7 engineers own your Oracle JDK 8 (LTS) incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- oracle-jdk
- release
- 8
- product Label
- Oracle JDK
- release Label
- 8 (LTS)
- codename
- lts
- true
- latest Version
- 8u501
- release Date
- 2014-03-18
- maintained
- true
- source Url
- https://endoflife.date/oracle-jdk
Lifecycle Dates
- End of Service Life
- Dec 31, 2030
- Last OEM Support
- Mar 31, 2022
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Oracle JDK 8 (LTS) — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Oracle JDK 8 (LTS)?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Oracle JDK 8 (LTS) when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Oracle JDK 8 (LTS) Support: Frequently Asked Questions
Is the Oracle OS Oracle JDK 8 (LTS) still supported?
Yes. The Oracle JDK 8 (LTS) is currently supported by Oracle OS, and third-party support is available as an alternative — issue management, vulnerability remediation, and compliance help independent of the vendor contract.
When is the Oracle OS Oracle JDK 8 (LTS) end of service life (EOSL) date?
Oracle OS lists the end of service life for the Oracle JDK 8 (LTS) as Dec 31, 2030.
Can I keep using the Oracle JDK 8 (LTS) after its EOSL date?
Yes. EOSL means Oracle OS stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Oracle JDK 8 (LTS) cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Oracle JDK 8 (LTS)
4 published CVEs affect the Oracle OS Oracle JDK 8 (LTS), including 2 rated critical or high severity. Our 24/7 engineers help you assess exposure, prioritize fixes and apply available patches.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2019-11068 | CRITICAL | 9.8 | Apr 10, 2019 | libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded. |
| CVE-2022-21476 | HIGH | 7.5 | Apr 19, 2022 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can resul |
| CVE-2018-11212 | MEDIUM | 6.5 | May 16, 2018 | An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file. |
| CVE-2021-41041 | MEDIUM | 5.3 | Apr 27, 2022 | In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification when verification is triggered by a MethodHandle invocation, allowing unverified methods to be invoked using MethodHandles. |