V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2016-3427
ANC
Critical KEVConfirmedExploit available

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to af…

CVSS
9.8
Critical
EPSS
0.93
p99
Published
2016-01-01
Updated
2023-05-12
Description

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.

Tags · CWE
KEVPre-auth
CWE-284
CAPEC-19
CAPEC-441
CAPEC-478
CAPEC-479
CAPEC-502
CAPEC-503
CAPEC-536
CAPEC-546
CAPEC-550
CAPEC-551
CAPEC-552
CAPEC-556
CAPEC-558
CAPEC-562
CAPEC-563
CAPEC-564
CAPEC-578
Affected products
Java-1.6.0-ibmJava-1.6.0-ibmJava-1.6.0-openjdkJava-1.6.0-openjdkJava-1.6.0-openjdkJava-1.6.0-sunJava-1.6.0-sunJava-1.6.0-sunJava-1.7.0-ibmJava-1.7.0-ibmJava-1.7.0-openjdkJava-1.7.0-openjdkJava-1.7.0-openjdkJava-1.7.0-oracleJava-1.7.0-oracleJava-1.7.0-oracleJava-1.7.1-ibmJava-1.7.1-ibm
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2016-01-01
Published
2023-05-12
Added to KEV
2023-05-12
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.933 · p99
Known exploited (KEV)
Yes
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-552 · CWE-284
└ via CAPEC-19 · CWE-284
└ via CAPEC-564 · CWE-284
└ via CAPEC-562 · CWE-284
└ via CAPEC-558 · CWE-284
└ via CAPEC-552 · CWE-284
└ via CAPEC-550 · CWE-284
└ via CAPEC-564 · CWE-284
└ via CAPEC-478 · CWE-284
└ via CAPEC-564 · CWE-284
└ via CAPEC-556 · CWE-284
└ via CAPEC-558 · CWE-284
└ via CAPEC-19 · CWE-284
└ via CAPEC-564 · CWE-284
└ via CAPEC-552 · CWE-284
└ via CAPEC-479 · CWE-284
└ via CAPEC-578 · CWE-284
Known exploits — Сканер-ВС
CVE-2016-3427
cisa · https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Enterprise
Affected software
ProductVendorStatus
Exploited
Exploited
java-1.6.0-ibmExploited
java-1.6.0-ibmExploited
java-1.6.0-openjdkExploited
java-1.6.0-openjdkExploited
java-1.6.0-openjdkExploited
java-1.6.0-sunExploited
java-1.6.0-sunExploited
java-1.6.0-sunExploited
java-1.7.0-ibmExploited
java-1.7.0-ibmExploited
java-1.7.0-openjdkExploited
java-1.7.0-openjdkExploited
java-1.7.0-openjdkExploited
java-1.7.0-oracleExploited
java-1.7.0-oracleExploited
java-1.7.0-oracleExploited
java-1.7.1-ibmExploited
java-1.7.1-ibmExploited
Source databases
ANC
DEB
CVE
RED
UBU
Related vulnerabilities