CVE-2016-3427
critical · 9.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2023-05-12Remediation due 2023-06-02
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
9.8
CVSS
92.3%
EPSS (exploit prob.)
100th
EPSS percentile
2016-04-21
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-284
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.7.0 |
| oracle | jdk | 1.8.0 |
| oracle | jre | 1.6.0 |
| oracle | jre | 1.7.0 |
| oracle | jre | 1.8.0 |
| oracle | jrockit | r28.3.9 |
| oracle | linux | 5 |
| oracle | linux | 6 |
| oracle | linux | 7 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 15.10 |
| canonical | ubuntu_linux | 16.04 |
| debian | debian_linux | 8.0 |
| netapp | e-series_santricity_management_plug-ins | all versions |
| netapp | e-series_santricity_storage_manager | all versions |
| netapp | e-series_santricity_web_services | all versions |
| netapp | oncommand_balance | all versions |
| netapp | oncommand_cloud_manager | all versions |
| netapp | oncommand_insight | all versions |
| netapp | oncommand_performance_manager | all versions |
| netapp | oncommand_report | all versions |
| netapp | oncommand_shift | all versions |
| netapp | oncommand_unified_manager | all versions |
| netapp | oncommand_unified_manager | all versions |
| netapp | oncommand_workflow_automation | all versions |
| netapp | storagegrid | <= 9.0.4 |
| netapp | vasa_provider_for_clustered_data_ontap | >= 7.2 |
| netapp | virtual_storage_console | >= 7.2 |
| apache | cassandra | >= 2.1.0, < 2.1.22 |
| apache | cassandra | >= 2.2.0, < 2.2.18 |
| apache | cassandra | >= 3.0.0, < 3.0.22 |
| apache | cassandra | >= 3.11.0, < 3.11.8 |
| apache | cassandra | 4.0.0 |
| redhat | satellite | 5.6 |
| redhat | satellite | 5.7 |
| redhat | enterprise_linux_desktop | 5.0 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_desktop | 7.0 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00009.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00012.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00021.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00026.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00039.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00040.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00042.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00058.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00059.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00061.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00067.html
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00002.html
- http://rhn.redhat.com/errata/RHSA-2016-0650.html
- http://rhn.redhat.com/errata/RHSA-2016-0651.html
- http://rhn.redhat.com/errata/RHSA-2016-0675.html
- http://rhn.redhat.com/errata/RHSA-2016-0676.html
- http://rhn.redhat.com/errata/RHSA-2016-0677.html
- http://rhn.redhat.com/errata/RHSA-2016-0678.html
- http://rhn.redhat.com/errata/RHSA-2016-0679.html
- http://rhn.redhat.com/errata/RHSA-2016-0701.html
- http://rhn.redhat.com/errata/RHSA-2016-0702.html
- http://rhn.redhat.com/errata/RHSA-2016-0708.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2016-3427