VulnerabilityAnalyzed
CVE-2016-3427
Oracle Java SE and JRockit Unspecified Vulnerability
KEVCRITICAL 9.8EPSS 92.3%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 2 June 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 92.33% probability · 100th percentile
- CISA KEV
- Listed 12 May 2023 · due 2 June 2023
- Weakness
- CWE-284
- Affected
- oracle/jdk · oracle/jre · oracle/jrockit · oracle/linux · canonical/ubuntu linux · debian/debian linux · netapp/e-series santricity management plug-ins · netapp/e-series santricity storage manager · netapp/e-series santricity web services · netapp/oncommand balance · netapp/oncommand cloud manager · netapp/oncommand insight · netapp/oncommand performance manager · netapp/oncommand report · netapp/oncommand shift · netapp/oncommand unified manager · netapp/oncommand workflow automation · netapp/storagegrid · netapp/vasa provider for clustered data ontap · netapp/virtual storage console · +18 more
- Source
- secalert_us@oracle.com
CISA notes
Apply updates per vendor instructions. https://www.oracle.com/security-alerts/cpuapr2016v3.html; https://nvd.nist.gov/vuln/detail/CVE-2016-3427
References
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00006.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00009.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00012.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00021.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00022.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00026.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00027.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00039.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00040.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00042.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00058.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00059.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00061.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00067.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00002.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0650.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0651.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0675.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0676.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0677.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0678.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0679.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0701.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0702.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0708.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0716.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0723.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1039.htmlThird Party Advisory
- http://www.debian.org/security/2016/dsa-3558Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2020/08/31/1Mailing List
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.