This application requires Javascript for optimal performance.

Oracle.Java.Software.Update.Weakness

Release Date

Jan 19, 2012

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This is an attack attempt against a Software Update Spoofing vulnerability in Oracle Java.

The vulnerability is caused because the "Java Update" mechanism of the vulnerable application insecurely validates new updates. A man-in-the-middle attacker may offer software that appears to originate from Oracle.

Affected Products

Oracle Java Runtime Environment (JRE) 6 update 29 and prior

Recommended Actions

Do not use the "Java Update" utility.
Currently we are not aware of any vendor supplied patches.

Coverage

IPS
VCM

Reference/s

https://portal.telussecuritylabs.com/threat/TSL20111212-06

Reference: VID-30726