10

CVE-2016-3427

Warnung
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Jdk Version 1.6.0 Update update113
Oracle ≫ Jdk Version 1.7.0 Update update99
Oracle ≫ Jdk Version 1.8.0 Update update77
Oracle ≫ Jre Version 1.6.0 Update update113
Oracle ≫ Jre Version 1.7.0 Update update99
Oracle ≫ Jre Version 1.8.0 Update update77
Oracle ≫ Jrockit Version r28.3.9
Oracle ≫ Linux Version 5 Update -
Oracle ≫ Linux Version 6 Update -
Oracle ≫ Linux Version 7 Update -
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 15.10
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Debian ≫ Debian Linux Version 8.0
Netapp ≫ E-series Santricity Management Plug-ins Version - SwPlatform vmware_vcenter
Netapp ≫ E-series Santricity Web Services Version - SwPlatform web_services_proxy
Netapp ≫ Oncommand Balance Version -
Netapp ≫ Oncommand Insight Version -
Netapp ≫ Oncommand Report Version -
Netapp ≫ Oncommand Shift Version -
Netapp ≫ Oncommand Unified Manager Version - SwPlatform 7-mode
Netapp ≫ Oncommand Unified Manager Version - SwPlatform clustered_data_ontap
Netapp ≫ Storagegrid Version <= 9.0.4
Netapp ≫ Virtual Storage Console SwPlatform vmware_vsphere Version >= 7.2
Apache ≫ Cassandra Version >= 2.1.0 < 2.1.22
Apache ≫ Cassandra Version >= 2.2.0 < 2.2.18
Apache ≫ Cassandra Version >= 3.0.0 < 3.0.22
Apache ≫ Cassandra Version >= 3.11.0 < 3.11.8
Apache ≫ Cassandra Version 4.0.0 Update beta1
Redhat ≫ Satellite Version 5.6
Redhat ≫ Satellite Version 5.7
Redhat ≫ Enterprise Linux Eus Version 6.7
Redhat ≫ Enterprise Linux Eus Version 7.2
Redhat ≫ Enterprise Linux Eus Version 7.3
Redhat ≫ Enterprise Linux Eus Version 7.4
Redhat ≫ Enterprise Linux Eus Version 7.5
Redhat ≫ Enterprise Linux Eus Version 7.6
Redhat ≫ Enterprise Linux Eus Version 7.7
Suse ≫ Manager Version 2.1
Suse ≫ Manager Proxy Version 2.1
Suse ≫ Openstack Cloud Version 5
Opensuse ≫ Leap Version 42.1
Opensuse ≫ Opensuse Version 13.1
Opensuse ≫ Opensuse Version 13.2
Suse ≫ Linux Enterprise Desktop Version 12 Update -
Suse ≫ Linux Enterprise Desktop Version 12 Update sp1
Suse ≫ Linux Enterprise Server Version 10 Update sp4 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 11 Update sp2 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 11 Update sp3 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 11 Update sp4
Suse ≫ Linux Enterprise Server Version 12 Update -
Suse ≫ Linux Enterprise Server Version 12 Update sp1

12.05.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog

Oracle Java SE and JRockit Unspecified Vulnerability

Schwachstelle

Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Management Extensions (JMX). This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 92.33% 0.998
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html
Patch
Vendor Advisory
https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
Patch
Third Party Advisory
https://access.redhat.com/errata/RHSA-2016:1430
Third Party Advisory
https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
http://www.debian.org/security/2016/dsa-3558
Third Party Advisory
Mailing List
https://security.gentoo.org/glsa/201606-18
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00006.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00009.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00012.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00021.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00022.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00026.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00027.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00039.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00040.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00042.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00058.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00059.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00061.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00067.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00002.html
Third Party Advisory
Mailing List
http://rhn.redhat.com/errata/RHSA-2016-0650.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0651.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0675.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0676.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0677.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0678.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0679.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0701.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0702.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0708.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0716.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0723.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-1039.html
Third Party Advisory
http://www.securitytracker.com/id/1035596
Third Party Advisory
Broken Link
VDB Entry
http://www.ubuntu.com/usn/USN-2963-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2964-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2972-1
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1216
Third Party Advisory
https://security.netapp.com/advisory/ntap-20160420-0001/
Third Party Advisory
https://kc.mcafee.com/corporate/index?page=content&id=SB10159
Broken Link
http://www.openwall.com/lists/oss-security/2020/08/31/1
Mailing List
http://www.securityfocus.com/bid/86421
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id/1037331
Third Party Advisory
Broken Link
VDB Entry
https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
https://lists.apache.org/thread.html/r5f48b16573a11fdf0b557cc3d1d71423ecde8ee771c29f32334fa948%40%3Cdev.cassandra.apache.org%3E
Third Party Advisory
Mailing List
https://lists.apache.org/thread.html/rc3abf40b06c511d5693baf707d6444bf7745e6a1e343e6f530a12258%40%3Cuser.cassandra.apache.org%3E
Third Party Advisory
Mailing List
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-3427
US Government Resource