CVE-2016-5597

Advisory lineage Upstream: 0 Downstream: 27
Modified
Published: 25 Oct 2016, 14:00
Last modified:04 Nov 2025, 21:08

Vulnerability Summary

Overall Risk (default)
low
24/100
CVSS Score
5.9 MEDIUM
v3.0 (nvd)
EPSS Score
1.44% LOW
1% probability -0.48%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

25 Oct 2016, 14:00
Published
Vulnerability first disclosed
04 Nov 2025, 21:08
Last Modified
Vulnerability information updated

Description

Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality via vectors related to Networking.

CVSS Metrics

  • v3.0MEDIUMScore: 5.9CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 1.44% Percentile: 81%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • oraclejdk

    1.6.0:update121 | 1.7.0:update111 | 1.8.0:update101 | 1.8.0:update102

  • oraclejre

    1.6.0:update121 | 1.7.0:update111 | 1.8.0:update101 | 1.8.0:update102

References (21)