By submitting a specially crafted XML document or image file to a Java 7u80 application, an attacker can trigger infinite loops or excessive memory consumption.
Option 1: Upgrade to a Supported Java Long-Term Support (LTS) Version
Leaving a Java 7u80 environment untouched is a severe compliance violation for frameworks like PCI-DSS, HIPAA, and SOC 2. Organizations must choose one of the following remediation paths immediately.