CVE-2016-5573

Advisory lineage Upstream: 0 Downstream: 27
Modified
Published: 25 Oct 2016, 14:00
Last modified:10 Oct 2024, 18:24

Vulnerability Summary

Overall Risk (default)
medium
34/100
CVSS Score
8.3 HIGH
v3.0 (nvd)
EPSS Score
3.92% LOW
4% probability +1.08%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

25 Oct 2016, 14:00
Published
Vulnerability first disclosed
10 Oct 2024, 18:24
Last Modified
Vulnerability information updated

Description

Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5582.

CVSS Metrics

  • v3.0HIGHScore: 8.3CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 3.92% Percentile: 89%

Techniques & Countermeasures

  • CWE-264Permissions, Privileges, and Access Controls

    Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.

Affected Systems

  • oraclejdk

    1.6.0:update121 | 1.7.0:update111 | 1.8.0:update101 | 1.8.0:update102

  • oraclejre

    1.6.0:update121 | 1.7.0:update111 | 1.8.0:update101 | 1.8.0:update102

References (20)