CVE-2016-3427

Confirmed PUBLISHED

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect...

Oracle · Java SE
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical

At a Glance

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.

cisa java nessus_scanner
CVE Published
Apr 21, 2016
Exploitation Reported
May 12, 2023
CVSS
9.8 Critical
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • openSUSE-SU-2016:1222 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00006...
  • RHSA-2016:0677 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2016-0677.html
  • SUSE-SU-2016:1299 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00039...
  • RHSA-2016:1039 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2016-1039.html
  • RHSA-2016:0701 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2016-0701.html
Show 54 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.