Get a Pentest and security assessment of your IT network.

News

Three-year-old IBM patch for critical Java flaw is broken

IBM issued a fix in a July 2013 update for its Java development kit for a critical vulnerability in its own Java implementation. The patch relied solely on the idea that hiding the vulnerable method deep in the code and behind a Proxy class would be sufficient to address the issue. IBM maintains its own implementation of the Java virtual machine and runtime. Security Explorations recently changed its vulnerability disclosure policy, saying that it will no longer tolerate broken patches for vulnerabilities that it has responsibly reported to vendors. The company will now publicly disclose how to bypass those fixes without notifying the vendors beforehand.”]

Source: https://www.csoonline.com/article/3052254/three-year-old-ibm-patch-for-critical-java-flaw-is-broken.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

FBI director floats international framework on access to encrypted data

News

The 'Disappearance' of Keith Alexander