CVE-2016-5582

Advisory lineage Upstream: 0 Downstream: 16
Modified
Published: 25 Oct 2016, 14:00
Last modified:10 Oct 2024, 18:23

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.6 CRITICAL
v3.0 (nvd)
EPSS Score
6.25% LOW
6% probability +1.97%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

25 Oct 2016, 14:00
Published
Vulnerability first disclosed
10 Oct 2024, 18:23
Last Modified
Vulnerability information updated

Description

Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5573.

CVSS Metrics

  • v3.0CRITICALScore: 9.6CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • v2.0HIGHScore: 9.3AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 6.25% Percentile: 91%

Techniques & Countermeasures

  • CWE-284Improper Access Control

    The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Affected Systems

  • oraclejdk

    1.6.0:update121 | 1.7.0:update111 | 1.8.0:update101 | 1.8.0:update102

  • oraclejre

    1.6.0:update121 | 1.7.0:update111 | 1.8.0:update101 | 1.8.0:update102

References (16)