HTTP: Oracle Java Garbage Collector Phantom Object References Handling Remote Code Execution

This signature detects attempts to exploit a known vulnerability against Oracle Java. A successful exploit can result in a remote code execution.

Extended Description

Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

Affected Products

Oracle jdk

References

BugTraq: 72142

CVE: CVE-2015-0395

Short Name
HTTP:STC:JAVA:PHANTOM-OBJ-RCE
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2015-0395 Code Collector Execution Garbage Handling Java Object Oracle Phantom References Remote bid:72142
Release Date
02/10/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Unknown
Vendors

Redhat

Opensuse

Oracle

Novell

Debian

Canonical

CVSS Score

9.3

Found a potential security threat?