Airlock WAF uses Java in the Configuration Center and in several add-on modules.
The Oracle Critical Patch Update for January 2017 includes updates for Java SE [1] which fixes 17 vulnerabilities.
Airlock WAF is not affected.
Details:
It is strongly recommended to apply the Java update to all client installations, or better to disable or even un-install Java from clients.