CVE-2016-3458Oracle JDK vulnerability

12 documents8 sources
Severity
4.3MEDIUMNVD
EPSS
2.6%
top 14.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 21
Latest updateMay 13

Description

Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; and Java SE Embedded 8u91 allows remote attackers to affect integrity via vectors related to CORBA.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

NVDoracle/jdk1.6.0, 1.7.0, 1.8.0+2
NVDoracle/jre1.6.0, 1.7.0, 1.8.0+2
NVDoracle/linux5.0, 6, 7+2

Patches

🔴Vulnerability Details

5
GHSA
GHSA-7whp-jqqm-w268: Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; and Java SE Embedded 8u91 allows remote attackers to affect integrity via vectors2022-05-13
OSV
openjdk-7 vulnerabilities2016-08-16
OSV
openjdk-8 vulnerabilities2016-07-27
CVEList
CVE-2016-3458: Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; and Java SE Embedded 8u91 allows remote attackers to affect integrity via vectors2016-07-21
OSV
CVE-2016-3458: Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; and Java SE Embedded 8u91 allows remote attackers to affect integrity via vectors2016-07-21

📋Vendor Advisories

5
Ubuntu
OpenJDK 6 vulnerabilities2016-09-12
Ubuntu
OpenJDK 7 vulnerabilities2016-08-16
Ubuntu
OpenJDK 8 vulnerabilities2016-07-27
Red Hat
OpenJDK: insufficient restrictions on the use of custom ValueHandler (CORBA, 8079718)2016-07-19
Debian
CVE-2016-3458: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; and Java SE ...2016

💬Community

1
Bugzilla
CVE-2016-3458 OpenJDK: insufficient restrictions on the use of custom ValueHandler (CORBA, 8079718)2016-07-18
CVE-2016-3458 — Oracle JDK vulnerability | cvebase