The Oracle Critical Patch Update for Januar 2016 includes updates for several Oracle products including Java SE [1].
Airlock WAF is not affected
Details:
CVE-2016-0494, CVE-2015-8126, CVE-2016-0402, CVE-2016-0448: Affects client deployments only
CVE-2016-0483: Affects the component AWT which is not used by Airlock WAF
CVE-2015-7575 (SLOTH): Affects MD5 hashes which are not used by Airlock WAF.
CVE-2016-0466: Affects the component JAXP which is used in the SOAP/XML filter. The vulnerability can enable Denial of Service attacks. Airlock WAF is not affected because the affected Java property totalEntitySizeLimit is not used.