Two more zero-day Java bugs discovered
Polish researchers find more flaws in Java 7 browser plug-in.


Java has been hit by the discovery of two more vulnerabilities. Polish security firm Security Explorations has reported the bugs to Oracle.
The security company said that it had submitted information about the bugs, including proof-of-concept exploits to Oracle.
"We had yet another look into Oracle's Java SE 7 software that was released by the company on Feb. 19," said Adam Gowdiak, in a posting to security forum, Seclists.org. "As a result, we have discovered two new security issues, which when combined together, can be successfully used to gain a complete Java security sandbox bypass in the environment of Java SE 7 Update 15 (1.7.0_15-b03)."
Gowdiak said that both new issues are specific to Java SE 7 only. "They allow toabuse the Reflection API in a particularly interesting way," he added.
"Without going into further details, everything indicates that a ball is in Oracle's court. Again."
The flaws do not affect Java 6, which Oracle has officially retired from support.
Gowdiak said in an update to the posting that Oracle has provided his firm results of its analysis and said that while one flaw had been confirmed as an issue, the other, dubbed "Issue 54" was "not treated as a vulnerability as it demonstrates the 'allowed behavior'".
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Gowdiak said he disagreed with Oracle's assessment of Issue 54.
"There is a mirror case corresponding to Issue 54 that leads to access denied condition and a security exception," he said. "That alone seems to be enough to contradict the "allowed behavior" claim by the company (is it possible to claim a non-security vulnerability when access is denied for a public API, but allowed for some private code path?)."
He warned Oracle that if it stuck with its original assessment, his company would have "no choice than to publish details of Issue 54".
The vulnerabilities are the latest in a slew of problems affecting the code. Twice this year Oracle has had to rush out emergency out-of-band patches to fix flaws in Java.
Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
Oracle breach claims spark war of words with security researchers
News A war of words has erupted between Oracle and cybersecurity researchers following claims the company suffered a security breach.
By Ross Kelly Published
-
“By this time next year, Oracle employees won't be using passwords” — Larry Ellison wants a biometric future in cybersecurity
News The Oracle CTO hit out at passwords, calling them insecure and easy to steal
By George Fitzmaurice Published
-
NetSuite vulnerability could leave thousands of websites exposed
News The issue stems from a misconfiguration of access controls in NetSuite's SuiteCommerce instances
By George Fitzmaurice Published
-
Oracle's massive advertising database operates without user consent, lawsuit claims
News Rights organisers have accused Oracle of collecting an undue level of sensitive data to identify consumers online
By Rory Bathgate Published
-
Oracle joins Cloudflare's Bandwidth Alliance
News Database giant will adjust cloud transfer fees for Cloudflare customers
By Danny Bradbury Published
-
Oracle won't let you turn off security ever again
News Larry Ellison: It was a mistake to let customers manage security features
By Joe Curtis Published
-
Microsoft warns users to be wary of fake Java updates
News Cybercriminals set malware trap for users worried by Java zero-day exploits.
By Jane McCallion Published
-
Calls for Java overhaul grow as more security flaws emerge
News Security experts suggest problems in the development cycle of Java could be to blame for recent security woes.
By Caroline Donnelly Published