Number: AV16-022
Date: 9 February 2015
Purpose
The purpose of this advisory is to bring attention to a recent Oracle Java SE security update.
Assessment
CCIRC is aware of a critical vulnerability in Oracle Java SE which could allow a remote attacker to execute arbitrary code without authentication .
Affected versions: Java SE prior to 6u113, 7u97 or 8u73
CVE Reference: CVE-2016-0603
Suggested action
CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.
References:
http://www.oracle.com/technetwork/topics/security/alert-cve-2016-0603-2874360.html