The first Oracle Critical Patch Update of 2018 contains fixes for 21 new vulnerabilities in the Java SE platform, 28.5 percent of which relate to deserialization flaws. As part of Waratek’s security research and analysis of the October 2017 Oracle CPU, two new deserialization vulnerabilities were identified in the Java platform that have been patched in the January 2018 CPU.
Read full news article on Dzone