HTTP: Oracle Java AtomicReferenceFieldUpdater Type Confusion

This signature detects attempts to exploit a known vulnerability against Oracle Java. The vulnerability is due to a type confusion flaw in AtomicReferenceFieldUpdater class. A remote unauthenticated attacker can exploit this vulnerability by enticing a user to visit a webpage containing a maliciously crafted Java applet. Successful exploitation could result in arbitrary code execution in the context of the currently logged-in user.

Extended Description

Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.

Affected Products

Oracle jdk

References

BugTraq: 68599

CVE: CVE-2014-4262

Short Name
HTTP:STC:JAVA:TYPECONF
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
AtomicReferenceFieldUpdater CVE-2014-4262 Confusion Java Oracle Type bid:68599
Release Date
08/06/2014
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3492
False Positive
Unknown
Vendors

Oracle

CVSS Score

9.3

Found a potential security threat?