CVE-2016-3427 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 92.3% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2023-06-02.
Description
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 92.33% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-284 |
| On CISA KEV | yes — remediate by 2023-06-02 |
| Public exploit | none known |
| Published | 2016-04-21 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Oracle Java SE and JRockit Unspecified Vulnerability |
|---|---|
| Added | 2023-05-12 |
| Due | 2023-06-02 |
| Vendor / product | Oracle / Java SE and JRockit |
| Ransomware use | none reported |
Affected (38)
| Vendor | Product |
|---|---|
| apache | cassandra |
| canonical | ubuntu linux |
| debian | debian linux |
| netapp | e-series santricity management plug-ins |
| netapp | e-series santricity storage manager |
| netapp | e-series santricity web services |
| netapp | oncommand balance |
| netapp | oncommand cloud manager |
| netapp | oncommand insight |
| netapp | oncommand performance manager |
| netapp | oncommand report |
| netapp | oncommand shift |
| netapp | oncommand unified manager |
| netapp | oncommand workflow automation |
| netapp | storagegrid |
| netapp | vasa provider for clustered data ontap |
| netapp | virtual storage console |
| opensuse | leap |
| opensuse | opensuse |
| oracle | jdk |
| oracle | jre |
| oracle | jrockit |
| oracle | linux |
| redhat | enterprise linux desktop |
| redhat | enterprise linux eus |
| redhat | enterprise linux server |
| redhat | enterprise linux server aus |
| redhat | enterprise linux server eus |
| redhat | enterprise linux server tus |
| redhat | enterprise linux workstation |
| redhat | satellite |
| suse | linux enterprise desktop |
| suse | linux enterprise module for legacy |
| suse | linux enterprise server |
| suse | linux enterprise software development kit |
| suse | manager |
| suse | manager proxy |
| suse | openstack cloud |
References
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00009.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00012.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00021.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00026.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00039.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00040.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00042.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00058.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00059.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00061.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00067.html
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00002.html
- http://rhn.redhat.com/errata/RHSA-2016-0650.html
- http://rhn.redhat.com/errata/RHSA-2016-0651.html
- http://rhn.redhat.com/errata/RHSA-2016-0675.html
- http://rhn.redhat.com/errata/RHSA-2016-0676.html
- http://rhn.redhat.com/errata/RHSA-2016-0677.html
→ the Explorer · watch your stack · NVD