CVE-2016-5597
Aliases:CGA-2frc-36wf-fgm3CGA-2gr9-9xvv-w8mrCGA-3946-wf23-25hgCGA-4694-6h8g-56q8CGA-52hh-mqv4-jhrpCGA-5g96-79pf-6g37CGA-5wj5-fmmj-g2r4CGA-6255-v4rc-6vv5CGA-6phg-62pf-953qCGA-92g8-c4v4-x4mhCGA-cxwv-783x-hh8pCGA-f855-588h-77j4CGA-fjpq-24rh-32rvCGA-gh6h-x5hw-vgqwCGA-gv6j-7jhh-6m9cCGA-hgrj-837f-jjq9CGA-jmx9-2pm5-2996CGA-m25v-87jp-q75pCGA-mj5c-mr9x-c29xCGA-mvxc-v44v-fmfvCGA-mxq5-q99x-xprqCGA-p96r-gvpq-p8mcCGA-pgrq-mfwg-86v8CGA-pjfg-6jgg-2933CGA-q838-pxmr-cr43CGA-qcj5-f3g6-2xh9CGA-rwc2-95mg-954hCGA-vc2r-368g-x565CGA-vq6w-m733-r843CGA-vq85-jm59-33p2CGA-vr87-vx3m-vmw9CGA-xxc9-p732-g395
Advisory lineage Upstream: 0 Downstream: 27
Modified
Published: 25 Oct 2016, 14:00
Last modified:04 Nov 2025, 21:08
Vulnerability Summary
Overall Risk (default)
low
24/100 CVSS Score
5.9 MEDIUM
v3.0 (nvd)
EPSS Score
3.94% LOW
4% probability +2.01%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
25 Oct 2016, 14:00
Published
Vulnerability first disclosed
04 Nov 2025, 21:08
Last Modified
Vulnerability information updated
Description
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality via vectors related to Networking.
CVSS Metrics
- v3.0•MEDIUM•Score: 5.9CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- v2.0•MEDIUM•Score: 4.3AV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS Trends
Current EPSS score: 3.94%• Percentile: 90%
Techniques & Countermeasures
- CWE-200•Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Affected Systems
- chainguard•openjdk-11-openj9-default-policy
< 0.53.0-r0
- chainguard•openjdk-17-openj9-default-policy
< 0.53.0-r0
- chainguard•openjdk-21-openj9-default-policy
< 0.53.0-r0
- chainguard•openjdk-25-openj9
< 0.59.0-r1
- chainguard•openjdk-25-openj9-dbg
< 0.59.0-r1
- chainguard•openjdk-25-openj9-default-jdk
< 0.59.0-r1
- chainguard•openjdk-25-openj9-default-jvm
< 0.59.0-r1
- chainguard•openjdk-25-openj9-jmods
< 0.59.0-r1
- chainguard•openjdk-25-openj9-jre
< 0.59.0-r1
- chainguard•openjdk-26-openj9
< 0.59.0-r1
- chainguard•openjdk-26-openj9-dbg
< 0.59.0-r1
- chainguard•openjdk-26-openj9-default-jdk
< 0.59.0-r1
- chainguard•openjdk-26-openj9-default-jvm
< 0.59.0-r1
- chainguard•openjdk-26-openj9-jmods
< 0.59.0-r1
- chainguard•openjdk-26-openj9-jre
< 0.59.0-r1
- chainguard•openjdk-8-openj9-dbg
< 0.53.0-r1
- oracle•jdk
1.6.0:update121 | 1.7.0:update111 | 1.8.0:update101 | 1.8.0:update102
- oracle•jre
1.6.0:update121 | 1.7.0:update111 | 1.8.0:update101 | 1.8.0:update102
References (21)
- http://www.debian.org/security/2016/dsa-3707
- https://security.netapp.com/advisory/ntap-20161019-0001/
- http://rhn.redhat.com/errata/RHSA-2016-2659.html
- http://rhn.redhat.com/errata/RHSA-2016-2136.html
- http://rhn.redhat.com/errata/RHSA-2016-2079.html
- http://www.ubuntu.com/usn/USN-3130-1
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
- http://rhn.redhat.com/errata/RHSA-2016-2137.html
- http://rhn.redhat.com/errata/RHSA-2016-2138.html
- https://security.gentoo.org/glsa/201701-43
- http://rhn.redhat.com/errata/RHSA-2016-2090.html
- https://security.gentoo.org/glsa/201611-04
- http://rhn.redhat.com/errata/RHSA-2017-0061.html
- https://access.redhat.com/errata/RHSA-2017:1216
- http://www.ubuntu.com/usn/USN-3154-1
- http://rhn.redhat.com/errata/RHSA-2016-2089.html
- http://www.securityfocus.com/bid/93636
- http://www.securitytracker.com/id/1037040
- http://rhn.redhat.com/errata/RHSA-2016-2088.html
- http://rhn.redhat.com/errata/RHSA-2016-2658.html
- http://www.openwall.com/lists/oss-security/2025/10/29/2