CVE-2016-3449
published 2016-04-21CVE-2016-3449: Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors…
PriorityP349high8.3CVSS 3.0
AVNACHPRNUIRSCCHIHAH
EPSS
4.01%
89.5th percentile
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Deployment.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjdk-8 | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
CVSS provenance
nvdv3.08.3HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vendor_debian8.3LOW
vendor_redhat8.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JDK: unspecified vulnerability fixed in 6u115, 7u101 and 8u91 (Deployment)
vendor_redhat·2016-04-19·CVSS 8.3
CVE-2016-3449 [HIGH] JDK: unspecified vulnerability fixed in 6u115, 7u101 and 8u91 (Deployment)
JDK: unspecified vulnerability fixed in 6u115, 7u101 and 8u91 (Deployment)
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Deployment.
Debian
CVE-2016-3449: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote ...
vendor_debian·2016·CVSS 8.3
CVE-2016-3449 [HIGH] CVE-2016-3449: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote ...
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Deployment.
Scope: local
sid: resolved
GHSA
GHSA-v7xg-gp2r-hx5f: Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via v
ghsa_unreviewed·2022-05-13
CVE-2016-3449 [HIGH] GHSA-v7xg-gp2r-hx5f: Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via v
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Deployment.
No detection rules found.
No public exploits indexed.
Qualys
Oracle Critical Patch Update April 2016 | Qualys
blogs_qualys·2016-04-22·CVSS 8.1
CVE-2016-0636 [HIGH] Oracle Critical Patch Update April 2016 | Qualys
This week Oracle released their quarterly Critical Patch Update (CPU) for April 2016. The CPU addresses 136 vulnerabilities in 49 products, including Java, Solaris, several middleware products, VirtualBox, the MySQL database and the original Oracle database.
Oracle does not mention any vulnerabilities that are under known attacks, but points out that there was an out-of-band release for Java to fix CVE-2016-0636 last month.
Java is one of the software packages that are constantly under attack. Java as a full fledged programming languages gives the attacker a large attack surface and then a wide array of tools to continue post-exploitation. This update fixes nine vulnerabilities with the most three most critical sporting a CVSS of 9.6. The top three apply only to client deployments of Jav
Qualys
Oracle Critical Patch Update April 2016 | Qualys
blogs_qualys·2016-04-22·CVSS 8.1
CVE-2016-0636 [HIGH] Oracle Critical Patch Update April 2016 | Qualys
This week Oracle released their quarterly Critical Patch Update (CPU) for April 2016. The CPU addresses 136 vulnerabilities in 49 products, including Java, Solaris, several middleware products, VirtualBox, the MySQL database and the original Oracle database.
Oracle does not mention any vulnerabilities that are under known attacks, but points out that there was an out-of-band release for Java to fix CVE-2016-0636 last month.
Java is one of the software packages that are constantly under attack. Java as a full fledged programming languages gives the attacker a large attack surface and then a wide array of tools to continue post-exploitation. This update fixes nine vulnerabilities with the most three most critical sporting a CVSS of 9.6. The top three apply only to client deployments of Jav
Bugzilla
CVE-2016-3449 Oracle JDK: unspecified vulnerability fixed in 6u115, 7u101 and 8u91 (Deployment)
bugzilla·2016-04-19·CVSS 8.3
CVE-2016-3449 [HIGH] CVE-2016-3449 Oracle JDK: unspecified vulnerability fixed in 6u115, 7u101 and 8u91 (Deployment)
CVE-2016-3449 Oracle JDK: unspecified vulnerability fixed in 6u115, 7u101 and 8u91 (Deployment)
Oracle Java SE 6u115, 7u101 and 8u91 fixes an unspecified vulnerability in the Deployment component (CVE-2016-3449). Upstream has CVSSv2 scored this issue as: 7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuapr2016-2881694.html#AppendixJAVA
Discussion:
This issue has been addressed in the following products:
Oracle Java for Red Hat Enterprise Linux 6
Oracle Java for Red Hat Enterprise Linux 7
Via RHSA-2016:0677 https://rhn.redhat.com/errata/RHSA-2016-0677.html
---
This issue has been addressed in the following products:
Oracle Java for Red Hat Enterprise Linux 7
Oracle Java for Red Hat Enterprise Linux 5
Oracle Java for Red Hat En
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00039.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00042.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00058.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00059.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00061.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00067.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0677.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0678.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0679.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0701.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0702.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0708.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0716.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1039.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.securityfocus.com/bid/86485http://www.securitytracker.com/id/1035596https://access.redhat.com/errata/RHSA-2016:1430https://access.redhat.com/errata/RHSA-2017:1216https://security.gentoo.org/glsa/201606-18https://security.netapp.com/advisory/ntap-20160420-0001/http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00039.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00042.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00058.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00059.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00061.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00067.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0677.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0678.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0679.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0701.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0702.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0708.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0716.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1039.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.securityfocus.com/bid/86485http://www.securitytracker.com/id/1035596https://access.redhat.com/errata/RHSA-2016:1430https://access.redhat.com/errata/RHSA-2017:1216https://security.gentoo.org/glsa/201606-18https://security.netapp.com/advisory/ntap-20160420-0001/
2016-04-21
Published