Vulnerability Intelligence Report
Oracle Java SE and JRockit Unspecified Vulnerability
CVE-2016-3427
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
CISA KEV
SSVC: Active Exploitation
Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:92.33%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-284 ↗CWE-284 Improper Access Control
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| oracle | jdk | 1.6.0, 1.7.0, 1.8.0 |
| oracle | jre | 1.6.0, 1.7.0, 1.8.0 |
| oracle | jrockit | r28.3.9 |
| oracle | linux | 5, 6, 7 |
| canonical | ubuntu_linux | 12.04, 14.04, 15.10, 16.04 |
| debian | debian_linux | 8.0 |
| netapp | e-series_santricity_management_plug-ins | all |
| netapp | e-series_santricity_storage_manager | all |
| netapp | e-series_santricity_web_services | all |
| netapp | oncommand_balance | all |
| netapp | oncommand_cloud_manager | all |
| netapp | oncommand_insight | all |
| netapp | oncommand_performance_manager | all |
| netapp | oncommand_report | all |
| netapp | oncommand_shift | all |
| netapp | oncommand_unified_manager | all |
| netapp | oncommand_workflow_automation | all |
| netapp | storagegrid | all |
| netapp | vasa_provider_for_clustered_data_ontap | all |
| netapp | virtual_storage_console | all |
| apache | cassandra | 4.0.0 |
| redhat | satellite | 5.6, 5.7 |
| redhat | enterprise_linux_desktop | 5.0, 6.0, 7.0 |
| redhat | enterprise_linux_eus | 6.7, 7.2, 7.3, 7.4, 7.5, 7.6, 7.7 |
| redhat | enterprise_linux_server | 5.0, 6.0, 7.0 |
| redhat | enterprise_linux_server_aus | 7.2, 7.3, 7.4, 7.6, 7.7 |
| redhat | enterprise_linux_server_eus | 6.7, 7.2 |
| redhat | enterprise_linux_server_tus | 7.2, 7.3, 7.6, 7.7 |
| redhat | enterprise_linux_workstation | 5.0, 6.0, 7.0 |
| suse | linux_enterprise_module_for_legacy | 12 |
| suse | manager | 2.1 |
| suse | manager_proxy | 2.1 |
| suse | openstack_cloud | 5 |
| opensuse | leap | 42.1 |
| opensuse | opensuse | 13.1, 13.2 |
| suse | linux_enterprise_desktop | 12 |
| suse | linux_enterprise_server | 10, 11, 12 |
| suse | linux_enterprise_software_development_kit | 11, 12 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Oracle · Hosted Service · USA |
| Reserved | 2016-03-17T00:00:00 |
| Published | 2016-04-21T10:00:00 |
| Patch Date | 2016-04-19 |
| Last Updated | 2025-10-21T23:55:53 |
Community Chatter & Buzz