← Back to CVE List
Vulnerability Intelligence Report
Oracle Java SE and JRockit Unspecified Vulnerability

CVE-2016-3427

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.

CISA KEV SSVC: Active Exploitation Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:92.33%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-284 ↗CWE-284 Improper Access Control

Affected Products & Versions

Vendor Product Affected Versions
oracle jdk 1.6.0, 1.7.0, 1.8.0
oracle jre 1.6.0, 1.7.0, 1.8.0
oracle jrockit r28.3.9
oracle linux 5, 6, 7
canonical ubuntu_linux 12.04, 14.04, 15.10, 16.04
debian debian_linux 8.0
netapp e-series_santricity_management_plug-ins all
netapp e-series_santricity_storage_manager all
netapp e-series_santricity_web_services all
netapp oncommand_balance all
netapp oncommand_cloud_manager all
netapp oncommand_insight all
netapp oncommand_performance_manager all
netapp oncommand_report all
netapp oncommand_shift all
netapp oncommand_unified_manager all
netapp oncommand_workflow_automation all
netapp storagegrid all
netapp vasa_provider_for_clustered_data_ontap all
netapp virtual_storage_console all
apache cassandra 4.0.0
redhat satellite 5.6, 5.7
redhat enterprise_linux_desktop 5.0, 6.0, 7.0
redhat enterprise_linux_eus 6.7, 7.2, 7.3, 7.4, 7.5, 7.6, 7.7
redhat enterprise_linux_server 5.0, 6.0, 7.0
redhat enterprise_linux_server_aus 7.2, 7.3, 7.4, 7.6, 7.7
redhat enterprise_linux_server_eus 6.7, 7.2
redhat enterprise_linux_server_tus 7.2, 7.3, 7.6, 7.7
redhat enterprise_linux_workstation 5.0, 6.0, 7.0
suse linux_enterprise_module_for_legacy 12
suse manager 2.1
suse manager_proxy 2.1
suse openstack_cloud 5
opensuse leap 42.1
opensuse opensuse 13.1, 13.2
suse linux_enterprise_desktop 12
suse linux_enterprise_server 10, 11, 12
suse linux_enterprise_software_development_kit 11, 12

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
92.334%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityOracle · Hosted Service · USA
Reserved2016-03-17T00:00:00
Published2016-04-21T10:00:00
Patch Date2016-04-19
Last Updated2025-10-21T23:55:53

LINK COPIED TO CLIPBOARD