CVE-2016-5554
Aliases:CGA-2gjq-3f4q-g5whCGA-2h6g-jq58-2cq9CGA-2v4h-rf57-xj4hCGA-35rp-rrv5-49qpCGA-458j-2228-g576CGA-4mwr-2wv5-p6j4CGA-567w-f5p3-gx7vCGA-6fh6-mxv3-vwfhCGA-6mg6-2f3p-jmg9CGA-6mv8-5vc2-g3c8CGA-7q7x-jmrq-37ggCGA-8424-qvf5-gxq7CGA-89hf-5fqm-g3xqCGA-chmp-727p-fpg4CGA-f885-hv3c-qxvjCGA-fc83-gjmf-hcf8CGA-g4w8-v775-r2cvCGA-ghvq-9283-g53rCGA-hr34-pghh-99mmCGA-jf9h-5h6h-8qpxCGA-jmv5-h63r-893rCGA-m65p-9635-9c8mCGA-p79q-whrc-jj45CGA-ph5f-q98v-3xjxCGA-pm4x-2g63-xcv6CGA-qcm8-v5jr-63pvCGA-rp3c-4mcm-r39fCGA-vw43-8j2f-5m96CGA-wf9q-5hrq-3cr4CGA-wjj2-4fhg-h6w4CGA-wjw8-4h4q-qf2gCGA-wv8j-7cmx-5rhf
Advisory lineage Upstream: 0 Downstream: 27
Modified
Published: 25 Oct 2016, 14:00
Last modified:10 Oct 2024, 18:27
Vulnerability Summary
Overall Risk (default)
low
18/100 CVSS Score
4.3 MEDIUM
v3.0 (nvd)
EPSS Score
3.1% LOW
3% probability +1.08%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
25 Oct 2016, 14:00
Published
Vulnerability first disclosed
10 Oct 2024, 18:27
Last Modified
Vulnerability information updated
Description
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors related to JMX.
CVSS Metrics
- v3.0•MEDIUM•Score: 4.3CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- v2.0•MEDIUM•Score: 4.3AV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS Trends
Current EPSS score: 3.10%• Percentile: 87%
Affected Systems
- chainguard•openjdk-11-openj9-default-policy
< 0.53.0-r0
- chainguard•openjdk-17-openj9-default-policy
< 0.53.0-r0
- chainguard•openjdk-21-openj9-default-policy
< 0.53.0-r0
- chainguard•openjdk-25-openj9
< 0.59.0-r1
- chainguard•openjdk-25-openj9-dbg
< 0.59.0-r1
- chainguard•openjdk-25-openj9-default-jdk
< 0.59.0-r1
- chainguard•openjdk-25-openj9-default-jvm
< 0.59.0-r1
- chainguard•openjdk-25-openj9-jmods
< 0.59.0-r1
- chainguard•openjdk-25-openj9-jre
< 0.59.0-r1
- chainguard•openjdk-26-openj9
< 0.59.0-r1
- chainguard•openjdk-26-openj9-dbg
< 0.59.0-r1
- chainguard•openjdk-26-openj9-default-jdk
< 0.59.0-r1
- chainguard•openjdk-26-openj9-default-jvm
< 0.59.0-r1
- chainguard•openjdk-26-openj9-jmods
< 0.59.0-r1
- chainguard•openjdk-26-openj9-jre
< 0.59.0-r1
- chainguard•openjdk-8-openj9-dbg
< 0.53.0-r1
- oracle•jdk
1.6.0:update121 | 1.7.0:update111 | 1.8.0:update101 | 1.8.0:update102
- oracle•jre
1.6.0:update121 | 1.7.0:update111 | 1.8.0:update101 | 1.8.0:update102
References (20)
- http://www.debian.org/security/2016/dsa-3707
- https://security.netapp.com/advisory/ntap-20161019-0001/
- http://rhn.redhat.com/errata/RHSA-2016-2659.html
- http://rhn.redhat.com/errata/RHSA-2016-2136.html
- http://rhn.redhat.com/errata/RHSA-2016-2079.html
- http://www.ubuntu.com/usn/USN-3130-1
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
- http://rhn.redhat.com/errata/RHSA-2016-2137.html
- http://rhn.redhat.com/errata/RHSA-2016-2138.html
- https://security.gentoo.org/glsa/201701-43
- http://rhn.redhat.com/errata/RHSA-2016-2090.html
- https://security.gentoo.org/glsa/201611-04
- http://rhn.redhat.com/errata/RHSA-2017-0061.html
- http://www.securityfocus.com/bid/93637
- https://access.redhat.com/errata/RHSA-2017:1216
- http://www.ubuntu.com/usn/USN-3154-1
- http://rhn.redhat.com/errata/RHSA-2016-2089.html
- http://www.securitytracker.com/id/1037040
- http://rhn.redhat.com/errata/RHSA-2016-2088.html
- http://rhn.redhat.com/errata/RHSA-2016-2658.html