5.9

CVE-2016-5597

Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality via vectors related to Networking.

Data is provided by the National Vulnerability Database (NVD)
OracleJdk Version1.6.0 Updateupdate121
OracleJdk Version1.7.0 Updateupdate111
OracleJdk Version1.8.0 Updateupdate101
OracleJdk Version1.8.0 Updateupdate102
OracleJre Version1.6.0 Updateupdate121
OracleJre Version1.7.0 Updateupdate111
OracleJre Version1.8.0 Updateupdate101
OracleJre Version1.8.0 Updateupdate102
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.93% 0.828
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.