CVE-2016-3485
published 2016-07-21CVE-2016-3485: Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; Java SE Embedded 8u91; and JRockit R28.3.10 allows local users to affect integrity via…
PriorityP48low2.9CVSS 3.0
AVLACHPRNUINSUCNILAN
EPSS
0.45%
36.6th percentile
Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; Java SE Embedded 8u91; and JRockit R28.3.10 allows local users to affect integrity via vectors related to Networking.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjdk-8 | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jrockit | — | — |
CVSS provenance
nvdv3.02.9LOWCVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
vendor_debian2.9LOW
vendor_redhat2.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c5cc-pp8q-5p3c: Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; Java SE Embedded 8u91; and JRockit R28
ghsa_unreviewed·2022-05-13
CVE-2016-3485 [LOW] GHSA-c5cc-pp8q-5p3c: Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; Java SE Embedded 8u91; and JRockit R28
Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; Java SE Embedded 8u91; and JRockit R28.3.10 allows local users to affect integrity via vectors related to Networking.
Red Hat
OpenJDK: weak authentication secret in Pipe implementation on Windows (Networking, 8145446)
vendor_redhat·2016-07-19·CVSS 2.9
CVE-2016-3485 [LOW] OpenJDK: weak authentication secret in Pipe implementation on Windows (Networking, 8145446)
OpenJDK: weak authentication secret in Pipe implementation on Windows (Networking, 8145446)
Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; Java SE Embedded 8u91; and JRockit R28.3.10 allows local users to affect integrity via vectors related to Networking.
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-sun (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.7.0-openjdk (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.7.0-oracle (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 6) - Not affected
Package: java-1.6.0-sun (Red Hat Enterprise Linux 6) - Not affected
Package: java-1.7.0-openjdk (Red Hat Enterprise Linux 6) - Not affected
Package: java-1.7.
Debian
CVE-2016-3485: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; Java SE Embe...
vendor_debian·2016·CVSS 2.9
CVE-2016-3485 [LOW] CVE-2016-3485: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; Java SE Embe...
Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; Java SE Embedded 8u91; and JRockit R28.3.10 allows local users to affect integrity via vectors related to Networking.
Scope: local
sid: resolved
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-09/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-09/msg00006.htmlhttp://lists.opensuse.org/opensuse-updates/2016-08/msg00028.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1036365https://kc.mcafee.com/corporate/index?page=content&id=SB10166https://security.gentoo.org/glsa/201610-08https://security.gentoo.org/glsa/201701-43https://security.netapp.com/advisory/ntap-20160721-0001/http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-09/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-09/msg00006.htmlhttp://lists.opensuse.org/opensuse-updates/2016-08/msg00028.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1036365https://kc.mcafee.com/corporate/index?page=content&id=SB10166https://security.gentoo.org/glsa/201610-08https://security.gentoo.org/glsa/201701-43https://security.netapp.com/advisory/ntap-20160721-0001/
2016-07-21
Published