peter bassill · operator
$ cve CVE-2016-3427 JSON

CVE-2016-3427 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 92.3% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2023-06-02.

Description

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS92.33% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-284
On CISA KEVyes — remediate by 2023-06-02
Public exploitnone known
Published2016-04-21
Last modified2026-06-17

CISA KEV

NameOracle Java SE and JRockit Unspecified Vulnerability
Added2023-05-12
Due2023-06-02
Vendor / productOracle / Java SE and JRockit
Ransomware usenone reported

Affected (38)

VendorProduct
apachecassandra
canonicalubuntu linux
debiandebian linux
netappe-series santricity management plug-ins
netappe-series santricity storage manager
netappe-series santricity web services
netapponcommand balance
netapponcommand cloud manager
netapponcommand insight
netapponcommand performance manager
netapponcommand report
netapponcommand shift
netapponcommand unified manager
netapponcommand workflow automation
netappstoragegrid
netappvasa provider for clustered data ontap
netappvirtual storage console
opensuseleap
opensuseopensuse
oraclejdk
oraclejre
oraclejrockit
oraclelinux
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server tus
redhatenterprise linux workstation
redhatsatellite
suselinux enterprise desktop
suselinux enterprise module for legacy
suselinux enterprise server
suselinux enterprise software development kit
susemanager
susemanager proxy
suseopenstack cloud

References

→ the Explorer  ·  watch your stack  ·  NVD