cbcvebase.
CVE-2016-3427
published 2016-04-21

CVE-2016-3427: Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2023-06-02
Exploited in the wild
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.

Affected

115 ranges· showing 25
VendorProductVersion rangeFixed in
apachecassandra
apachecassandra>= 2.1.0 < 2.1.222.1.22
apachecassandra>= 2.2.0 < 2.2.182.2.18
apachecassandra>= 3.0.0 < 3.0.223.0.22
apachecassandra>= 3.11.0 < 3.11.83.11.8
apachetomcat< 6.0.486.0.48
apachetomcat
apachetomcat
apachetomcat>= 7.0.0 < 7.0.737.0.73
apachetomcat>= 8.0 < 8.0.398.0.39
apachetomcat>= 8.5.0 < 8.5.78.5.7
apache_software_foundationapache_tomcat
apache_software_foundationapache_tomcat
apache_software_foundationapache_tomcat
apache_software_foundationapache_tomcat
apache_software_foundationapache_tomcat
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianopenjdk-8< openjdk-8 8u91-b14-1 (sid)openjdk-8 8u91-b14-1 (sid)
debiantomcat9
netappstoragegrid<= 9.0.4
netappvasa_provider_for_clustered_data_ontap>= 7.2

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa9.8CRITICAL
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL