SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-0448

Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66, and Java SE Embedded 8u65 allows remote authenticated users to affect confidentiality via vectors related to JMX.

MEDIUM 4.0EPSS 3.53%

Does this matter?

Lower severity and a low EPSS score (3.53%). Track it; it rarely justifies an emergency change on its own.

Description

Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66, and Java SE Embedded 8u65 allows remote authenticated users to affect confidentiality via vectors related to JMX.

CVSS 2.0
4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS
3.53% probability · 89th percentile
CISA KEV
Not listed
Affected
oracle/jdk · oracle/jre · canonical/ubuntu linux
Source
secalert_us@oracle.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.