CVE-2016-5582
Aliases:CGA-25cc-xq75-h5c2CGA-446f-9w5h-64xmCGA-46rw-5hjm-46x5CGA-5r89-986q-hwmhCGA-6ppg-46f4-mmwhCGA-72r2-7mjv-64p9CGA-8gwp-4fxh-7629CGA-97f7-2w5x-g4qwCGA-9gcp-297w-vc73CGA-9x82-3xcj-7phxCGA-c267-x5g5-v39pCGA-cpcg-vv9x-cq8jCGA-gf74-69pf-44cvCGA-gjvw-2xp9-m6w2CGA-gr56-qj2x-22qfCGA-h6w3-rjr7-fw2hCGA-hf2x-cjfc-q625CGA-j8q6-j3c3-qh26CGA-jm6c-x287-pwwrCGA-p469-8cvv-895cCGA-p4r4-27pc-mxf2CGA-pfx2-964w-jvx7CGA-pjmr-3q3j-4cppCGA-q9mq-xhcw-gpjcCGA-qgpx-8wcf-mchwCGA-qmh7-g7vx-j8fvCGA-qqmm-57jh-77qrCGA-r8wg-2cqv-433qCGA-v3j8-3x4p-2vr6CGA-wj28-6625-63rrCGA-xh93-f8xj-p8r5CGA-xw23-977c-wjq5
Advisory lineage Upstream: 0 Downstream: 16
Modified
Published: 25 Oct 2016, 14:00
Last modified:10 Oct 2024, 18:23
Vulnerability Summary
Overall Risk (default)
high
70/100 CVSS Score
9.6 CRITICAL
v3.0 (nvd)
EPSS Score
5.44% LOW
5% probability +1.15%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
25 Oct 2016, 14:00
Published
Vulnerability first disclosed
10 Oct 2024, 18:23
Last Modified
Vulnerability information updated
Description
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5573.
CVSS Metrics
- v3.0•CRITICAL•Score: 9.6CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- v2.0•HIGH•Score: 9.3AV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 5.44%• Percentile: 92%
Techniques & Countermeasures
- CWE-284•Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Affected Systems
- chainguard•openjdk-11-openj9-default-policy
< 0.53.0-r0
- chainguard•openjdk-17-openj9-default-policy
< 0.53.0-r0
- chainguard•openjdk-21-openj9-default-policy
< 0.53.0-r0
- chainguard•openjdk-25-openj9
< 0.59.0-r1
- chainguard•openjdk-25-openj9-dbg
< 0.59.0-r1
- chainguard•openjdk-25-openj9-default-jdk
< 0.59.0-r1
- chainguard•openjdk-25-openj9-default-jvm
< 0.59.0-r1
- chainguard•openjdk-25-openj9-jmods
< 0.59.0-r1
- chainguard•openjdk-25-openj9-jre
< 0.59.0-r1
- chainguard•openjdk-26-openj9
< 0.59.0-r1
- chainguard•openjdk-26-openj9-dbg
< 0.59.0-r1
- chainguard•openjdk-26-openj9-default-jdk
< 0.59.0-r1
- chainguard•openjdk-26-openj9-default-jvm
< 0.59.0-r1
- chainguard•openjdk-26-openj9-jmods
< 0.59.0-r1
- chainguard•openjdk-26-openj9-jre
< 0.59.0-r1
- chainguard•openjdk-8-openj9-dbg
< 0.53.0-r1
- oracle•jdk
1.6.0:update121 | 1.7.0:update111 | 1.8.0:update101 | 1.8.0:update102
- oracle•jre
1.6.0:update121 | 1.7.0:update111 | 1.8.0:update101 | 1.8.0:update102
References (16)
- http://www.debian.org/security/2016/dsa-3707
- https://security.netapp.com/advisory/ntap-20161019-0001/
- http://www.securityfocus.com/bid/93623
- http://rhn.redhat.com/errata/RHSA-2016-2079.html
- http://www.ubuntu.com/usn/USN-3130-1
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
- https://security.gentoo.org/glsa/201701-43
- http://rhn.redhat.com/errata/RHSA-2016-2090.html
- https://security.gentoo.org/glsa/201611-04
- http://rhn.redhat.com/errata/RHSA-2017-0061.html
- http://www.ubuntu.com/usn/USN-3154-1
- http://rhn.redhat.com/errata/RHSA-2016-2089.html
- http://www.securitytracker.com/id/1037040
- http://rhn.redhat.com/errata/RHSA-2016-2088.html
- http://rhn.redhat.com/errata/RHSA-2016-2658.html
- https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E