Security research team flags Oracle Java 7 patch flaw
Security Explorations claim to have uncovered an undisclosed flaw in the software giant's out-of-band web browser fix.


Polish researchers from IT firm Security Explorations claim to have found a flaw in the security update rushed out last week to fix Oracle's Java 7 vulnerability.
The flaw in the update could be exploited to escape the Java sandbox and run arbitrary code on the operating system, the researchers have claimed.
Oracle released the patch last Thursday, and the following day the Security Explorations team alerted the software giant to the flaw.
The Polish researcher has not disclosed specific details on how the flaw would work as a security precaution.
Security Explorations' chief executive Adam Gowdiak wrote on security website Seclists.org that the "code successfully demonstrates a complete JVM sandbox bypass in the environment of a latest Java SE software (version 7 Update 7 released on Aug 30, 2012).
"The reason for it is a new security issue discovered, that made exploitation of some of our not yet addressed bugs possible to exploit again," he added.
Oracle was forced to release an out-of-band patch to fix the previous Java 7 zero-day exploit, which the Polish researchers claimed to have spotted back in April.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The Oracle advisory said: "These vulnerabilities are not applicable to Java running on servers or standalone Java desktop applications. They also do not affect Oracle server-based software."
The email illustrates the ingenuity and speed at which cyber-criminals operate.
Meanwhile, email scammers have already attempted to cash-in on the Java 7 issue by directing users to web pages containing the exploit.
The emails purport to be from Amazon and were flagged as fake by security vendor Websense in an alert sent out earlier today.
Xue Yang, a Websense security researcher, said: "[The email] further illustrates the ingenuity and speed at which cyber-criminals package and propagate malicious content along with social-engineering techniques to exploit both recent software vulnerabilities and the trusting nature of end-users."
Users have been advised to uninstall Java from systems if there is no need to use the software.
Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard Published
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd Published
-
Oracle breach claims spark war of words with security researchers
News A war of words has erupted between Oracle and cybersecurity researchers following claims the company suffered a security breach.
By Ross Kelly Published
-
“By this time next year, Oracle employees won't be using passwords” — Larry Ellison wants a biometric future in cybersecurity
News The Oracle CTO hit out at passwords, calling them insecure and easy to steal
By George Fitzmaurice Published
-
NetSuite vulnerability could leave thousands of websites exposed
News The issue stems from a misconfiguration of access controls in NetSuite's SuiteCommerce instances
By George Fitzmaurice Published
-
Oracle's massive advertising database operates without user consent, lawsuit claims
News Rights organisers have accused Oracle of collecting an undue level of sensitive data to identify consumers online
By Rory Bathgate Published
-
Oracle joins Cloudflare's Bandwidth Alliance
News Database giant will adjust cloud transfer fees for Cloudflare customers
By Danny Bradbury Published
-
Oracle won't let you turn off security ever again
News Larry Ellison: It was a mistake to let customers manage security features
By Joe Curtis Published
-
Two more zero-day Java bugs discovered
News Polish researchers find more flaws in Java 7 browser plug-in.
By Rene Millman Published
-
Microsoft warns users to be wary of fake Java updates
News Cybercriminals set malware trap for users worried by Java zero-day exploits.
By Jane McCallion Published