CVE-2016-5542
Aliases:CGA-27g4-wjj8-hf22CGA-2crh-gc6p-57qjCGA-2cvq-7845-6qx9CGA-2mxp-hpfc-c7p6CGA-33vf-54mv-4fxvCGA-34vg-6842-35r8CGA-369c-fpxr-4r8jCGA-3rhp-m38f-75gwCGA-67hv-36g3-cc3vCGA-7688-9r9r-2fc8CGA-792c-rv6h-g9hxCGA-79cj-v975-4f7vCGA-7r86-5qgw-f8f4CGA-87v9-v4ff-4mm3CGA-9qch-cfx9-jh28CGA-c5q5-2v92-f4f5CGA-f8mw-v8mh-m69rCGA-gw55-64ch-7xw7CGA-h3cq-ff8w-4898CGA-h6qc-g6pg-whhrCGA-hm7x-qhqr-hp8jCGA-j96f-wp4p-ggppCGA-m4j6-qp9x-j2xqCGA-mq6j-v3mh-v9p6CGA-mx9p-8xj2-6pm3CGA-pc6w-5g7w-hhwrCGA-pf33-4cv5-fc6wCGA-qg25-4x5j-58xcCGA-rc27-8f37-g684CGA-v452-9pv9-8q9xCGA-vwgv-m6h6-5mqmCGA-wj4r-qc89-x757
Advisory lineage Upstream: 0 Downstream: 27
Modified
Published: 25 Oct 2016, 14:00
Last modified:10 Oct 2024, 18:28
Vulnerability Summary
Overall Risk (default)
low
18/100 CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
2.79% LOW
3% probability +0.78%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
25 Oct 2016, 14:00
Published
Vulnerability first disclosed
10 Oct 2024, 18:28
Last Modified
Vulnerability information updated
Description
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors related to Libraries.
CVSS Metrics
- v3.0•LOW•Score: 3.1CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
- v2.0•MEDIUM•Score: 4.3AV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS Trends
Current EPSS score: 2.79%• Percentile: 86%
Affected Systems
- chainguard•openjdk-11-openj9-default-policy
< 0.53.0-r0
- chainguard•openjdk-17-openj9-default-policy
< 0.53.0-r0
- chainguard•openjdk-21-openj9-default-policy
< 0.53.0-r0
- chainguard•openjdk-25-openj9
< 0.59.0-r1
- chainguard•openjdk-25-openj9-dbg
< 0.59.0-r1
- chainguard•openjdk-25-openj9-default-jdk
< 0.59.0-r1
- chainguard•openjdk-25-openj9-default-jvm
< 0.59.0-r1
- chainguard•openjdk-25-openj9-jmods
< 0.59.0-r1
- chainguard•openjdk-25-openj9-jre
< 0.59.0-r1
- chainguard•openjdk-26-openj9
< 0.59.0-r1
- chainguard•openjdk-26-openj9-dbg
< 0.59.0-r1
- chainguard•openjdk-26-openj9-default-jdk
< 0.59.0-r1
- chainguard•openjdk-26-openj9-default-jvm
< 0.59.0-r1
- chainguard•openjdk-26-openj9-jmods
< 0.59.0-r1
- chainguard•openjdk-26-openj9-jre
< 0.59.0-r1
- chainguard•openjdk-8-openj9-dbg
< 0.53.0-r1
- oracle•jdk
1.6.0:update121 | 1.7.0:update111 | 1.8.0:update101 | 1.8.0:update102
- oracle•jre
1.6.0:update121 | 1.7.0:update111 | 1.8.0:update101 | 1.8.0:update102
References (20)
- http://www.debian.org/security/2016/dsa-3707
- https://security.netapp.com/advisory/ntap-20161019-0001/
- http://rhn.redhat.com/errata/RHSA-2016-2659.html
- http://rhn.redhat.com/errata/RHSA-2016-2136.html
- http://rhn.redhat.com/errata/RHSA-2016-2079.html
- http://www.ubuntu.com/usn/USN-3130-1
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
- http://rhn.redhat.com/errata/RHSA-2016-2137.html
- http://rhn.redhat.com/errata/RHSA-2016-2138.html
- https://security.gentoo.org/glsa/201701-43
- http://rhn.redhat.com/errata/RHSA-2016-2090.html
- https://security.gentoo.org/glsa/201611-04
- http://www.securityfocus.com/bid/93643
- http://rhn.redhat.com/errata/RHSA-2017-0061.html
- https://access.redhat.com/errata/RHSA-2017:1216
- http://www.ubuntu.com/usn/USN-3154-1
- http://rhn.redhat.com/errata/RHSA-2016-2089.html
- http://www.securitytracker.com/id/1037040
- http://rhn.redhat.com/errata/RHSA-2016-2088.html
- http://rhn.redhat.com/errata/RHSA-2016-2658.html