VulnerabilityModified
CVE-2016-3550
Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality via vectors related to Hotspot.
MEDIUM 4.3EPSS 3.07%
Does this matter?
Lower severity and a low EPSS score (3.07%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality via vectors related to Hotspot.
- CVSS 3.0
- 4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- EPSS
- 3.07% probability · 87th percentile
- CISA KEV
- Not listed
- Affected
- oracle/linux · oracle/jdk · oracle/jre
- Source
- secalert_us@oracle.com
References
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00011.html
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00032.html
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00033.html
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00034.html
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00035.html
- http://lists.opensuse.org/opensuse-updates/2016-08/msg00028.html
- http://rhn.redhat.com/errata/RHSA-2016-1504.html
- http://rhn.redhat.com/errata/RHSA-2016-1776.html
- http://www.debian.org/security/2016/dsa-3641
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlPatch, Vendor Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlVendor Advisory
- http://www.securityfocus.com/bid/91787Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/91951
- http://www.securitytracker.com/id/1036365
- http://www.ubuntu.com/usn/USN-3043-1
- http://www.ubuntu.com/usn/USN-3062-1
- http://www.ubuntu.com/usn/USN-3077-1
- https://access.redhat.com/errata/RHSA-2016:1458
- https://access.redhat.com/errata/RHSA-2016:1475
- https://access.redhat.com/errata/RHSA-2016:1476
- https://access.redhat.com/errata/RHSA-2016:1477
- https://security.gentoo.org/glsa/201610-08
- https://security.gentoo.org/glsa/201701-43
- https://security.netapp.com/advisory/ntap-20160721-0001/
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00011.html
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00032.html
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00033.html
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00034.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.