CVE-2016-3427

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect...

Basic Information

CVE State
PUBLISHED
Reserved Date
March 17, 2016
Published Date
April 21, 2016
Last Updated
October 08, 2024
Vendor
Oracle
Product
Java SE
Description
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
Tags
cisa

CVSS Scores

CVSS v3.1

9.8 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0

10.0

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2023-05-12 00:00:00 UTC) Source

References

http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00006.html http://rhn.redhat.com/errata/RHSA-2016-0677.html http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00039.html http://rhn.redhat.com/errata/RHSA-2016-1039.html http://rhn.redhat.com/errata/RHSA-2016-0701.html http://www.ubuntu.com/usn/USN-2972-1 http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00042.html http://www.securitytracker.com/id/1037331 http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00002.html http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00012.html http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00026.html http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00040.html http://rhn.redhat.com/errata/RHSA-2016-0676.html https://access.redhat.com/errata/RHSA-2016:1430 https://security.netapp.com/advisory/ntap-20160420-0001/ http://rhn.redhat.com/errata/RHSA-2016-0708.html http://rhn.redhat.com/errata/RHSA-2016-0723.html http://rhn.redhat.com/errata/RHSA-2016-0651.html http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00058.html http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00021.html http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00059.html https://kc.mcafee.com/corporate/index?page=content&id=SB10159 http://www.ubuntu.com/usn/USN-2964-1 http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00009.html http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00067.html https://security.gentoo.org/glsa/201606-18 http://rhn.redhat.com/errata/RHSA-2016-0716.html http://www.securitytracker.com/id/1035596 http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00027.html http://www.ubuntu.com/usn/USN-2963-1 http://rhn.redhat.com/errata/RHSA-2016-0675.html http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00022.html http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00061.html http://rhn.redhat.com/errata/RHSA-2016-0702.html http://rhn.redhat.com/errata/RHSA-2016-0679.html https://access.redhat.com/errata/RHSA-2017:1216 http://www.debian.org/security/2016/dsa-3558 http://rhn.redhat.com/errata/RHSA-2016-0678.html http://www.securityfocus.com/bid/86421 http://rhn.redhat.com/errata/RHSA-2016-0650.html https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3E https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3E https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3E https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3E https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3E https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3E https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3E https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3E https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3E https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.org%3E https://lists.apache.org/thread.html/rc3abf40b06c511d5693baf707d6444bf7745e6a1e343e6f530a12258%40%3Cuser.cassandra.apache.org%3E https://lists.apache.org/thread.html/r5f48b16573a11fdf0b557cc3d1d71423ecde8ee771c29f32334fa948%40%3Cdev.cassandra.apache.org%3E http://www.openwall.com/lists/oss-security/2020/08/31/1

Known Exploited Vulnerability Information

Source Added Date
CISA 2023-05-12 00:00:00 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel