CVE-2016-5573
Vulnerability Summary
Timeline
Description
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5582.
CVSS Metrics
- v3.0•HIGH•Score: 8.3CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
- v2.0•MEDIUM•Score: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS Trends
Current EPSS score: 3.26%• Percentile: 88%
Techniques & Countermeasures
- CWE-264•Permissions, Privileges, and Access Controls
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Affected Systems
- chainguard•openjdk-11-openj9-default-policy
< 0.53.0-r0
- chainguard•openjdk-17-openj9-default-policy
< 0.53.0-r0
- chainguard•openjdk-21-openj9-default-policy
< 0.53.0-r0
- chainguard•openjdk-25-openj9
< 0.59.0-r1
- chainguard•openjdk-25-openj9-dbg
< 0.59.0-r1
- chainguard•openjdk-25-openj9-default-jdk
< 0.59.0-r1
- chainguard•openjdk-25-openj9-default-jvm
< 0.59.0-r1
- chainguard•openjdk-25-openj9-jmods
< 0.59.0-r1
- chainguard•openjdk-25-openj9-jre
< 0.59.0-r1
- chainguard•openjdk-26-openj9
< 0.59.0-r1
- chainguard•openjdk-26-openj9-dbg
< 0.59.0-r1
- chainguard•openjdk-26-openj9-default-jdk
< 0.59.0-r1
- chainguard•openjdk-26-openj9-default-jvm
< 0.59.0-r1
- chainguard•openjdk-26-openj9-jmods
< 0.59.0-r1
- chainguard•openjdk-26-openj9-jre
< 0.59.0-r1
- chainguard•openjdk-8-openj9-dbg
< 0.53.0-r1
- oracle•jdk
1.6.0:update121 | 1.7.0:update111 | 1.8.0:update101 | 1.8.0:update102
- oracle•jre
1.6.0:update121 | 1.7.0:update111 | 1.8.0:update101 | 1.8.0:update102
References (20)
- http://www.debian.org/security/2016/dsa-3707
- https://security.netapp.com/advisory/ntap-20161019-0001/
- http://rhn.redhat.com/errata/RHSA-2016-2659.html
- http://rhn.redhat.com/errata/RHSA-2016-2136.html
- http://rhn.redhat.com/errata/RHSA-2016-2079.html
- http://www.securityfocus.com/bid/93628
- http://www.ubuntu.com/usn/USN-3130-1
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
- http://rhn.redhat.com/errata/RHSA-2016-2137.html
- http://rhn.redhat.com/errata/RHSA-2016-2138.html
- https://security.gentoo.org/glsa/201701-43
- http://rhn.redhat.com/errata/RHSA-2016-2090.html
- https://security.gentoo.org/glsa/201611-04
- http://rhn.redhat.com/errata/RHSA-2017-0061.html
- https://access.redhat.com/errata/RHSA-2017:1216
- http://www.ubuntu.com/usn/USN-3154-1
- http://rhn.redhat.com/errata/RHSA-2016-2089.html
- http://www.securitytracker.com/id/1037040
- http://rhn.redhat.com/errata/RHSA-2016-2088.html
- http://rhn.redhat.com/errata/RHSA-2016-2658.html