SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2016-3427

Oracle Java SE and JRockit Unspecified Vulnerability

KEVCRITICAL 9.8EPSS 92.3%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 2 June 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
92.33% probability · 100th percentile
CISA KEV
Listed 12 May 2023 · due 2 June 2023
Weakness
CWE-284
Affected
oracle/jdk · oracle/jre · oracle/jrockit · oracle/linux · canonical/ubuntu linux · debian/debian linux · netapp/e-series santricity management plug-ins · netapp/e-series santricity storage manager · netapp/e-series santricity web services · netapp/oncommand balance · netapp/oncommand cloud manager · netapp/oncommand insight · netapp/oncommand performance manager · netapp/oncommand report · netapp/oncommand shift · netapp/oncommand unified manager · netapp/oncommand workflow automation · netapp/storagegrid · netapp/vasa provider for clustered data ontap · netapp/virtual storage console · +18 more
Source
secalert_us@oracle.com

CISA notes

Apply updates per vendor instructions. https://www.oracle.com/security-alerts/cpuapr2016v3.html; https://nvd.nist.gov/vuln/detail/CVE-2016-3427

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.