It was discovered that the RemoteObjectInvocationHandler class in the RMI component of OpenJDK did not check if object proxy is an instance of a proxy class and that it uses correct invocation handler. An untrusted Java application or applet could use this flaw to bypass certain Java sandbox restrictions by gaining access to data that should by protected by the sandbox.
Public now via Oracle Critical Patch Update - October 2015. Fixed in Oracle Java SE 6u105, 7u91, and 8u65. External References: http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html#AppendixJAVA
This issue has been addressed in the following products: Red Hat Enterprise Linux 5 Via RHSA-2015:1921 https://rhn.redhat.com/errata/RHSA-2015-1921.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 7 Via RHSA-2015:1920 https://rhn.redhat.com/errata/RHSA-2015-1920.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 7 Via RHSA-2015:1919 https://rhn.redhat.com/errata/RHSA-2015-1919.html
This issue has been addressed in the following products: Oracle Java for Red Hat Enterprise Linux 7 Oracle Java for Red Hat Enterprise Linux 5 Oracle Java for Red Hat Enterprise Linux 6 Via RHSA-2015:1928 https://rhn.redhat.com/errata/RHSA-2015-1928.html
This issue has been addressed in the following products: Oracle Java for Red Hat Enterprise Linux 7 Oracle Java for Red Hat Enterprise Linux 6 Via RHSA-2015:1926 https://rhn.redhat.com/errata/RHSA-2015-1926.html
This issue has been addressed in the following products: Oracle Java for Red Hat Enterprise Linux 7 Oracle Java for Red Hat Enterprise Linux 5 Oracle Java for Red Hat Enterprise Linux 6 Via RHSA-2015:1927 https://rhn.redhat.com/errata/RHSA-2015-1927.html
OpenJDK8 upstream commit: http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/cf0cf52d0c6c
This issue has been addressed in the following products: Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 7 Via RHSA-2015:2086 https://rhn.redhat.com/errata/RHSA-2015-2086.html
This issue has been addressed in the following products: Supplementary for Red Hat Enterprise Linux 6 Supplementary for Red Hat Enterprise Linux 5 Via RHSA-2015:2508 https://rhn.redhat.com/errata/RHSA-2015-2508.html
This issue has been addressed in the following products: Supplementary for Red Hat Enterprise Linux 5 Via RHSA-2015:2507 https://rhn.redhat.com/errata/RHSA-2015-2507.html
This issue has been addressed in the following products: Supplementary for Red Hat Enterprise Linux 7 Via RHSA-2015:2509 https://rhn.redhat.com/errata/RHSA-2015-2509.html
This issue has been addressed in the following products: Supplementary for Red Hat Enterprise Linux 6 Supplementary for Red Hat Enterprise Linux 7 Via RHSA-2015:2506 https://rhn.redhat.com/errata/RHSA-2015-2506.html
This issue has been addressed in the following products: Supplementary for Red Hat Enterprise Linux 5 Supplementary for Red Hat Enterprise Linux 6 Via RHSA-2015:2518 https://rhn.redhat.com/errata/RHSA-2015-2518.html
This issue has been addressed in the following products: Red Hat Satellite 5.6 Red Hat Satellite 5.7 Via RHSA-2016:1430 https://access.redhat.com/errata/RHSA-2016:1430