CVE-2016-5536
published 2016-10-25CVE-2016-5536: Unspecified vulnerability in the Oracle Platform Security for Java component in Oracle Fusion Middleware 12.1.3.0.0, 12.2.1.0.0, and 12.2.1.1.0 allows remote…
PriorityP342high7.6CVSS 3.0
AVNACLPRLUINSUCHILAL
EPSS
1.59%
72.8th percentile
Unspecified vulnerability in the Oracle Platform Security for Java component in Oracle Fusion Middleware 12.1.3.0.0, 12.2.1.0.0, and 12.2.1.1.0 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2016-8281.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | platform_security_for_java | — | — |
| oracle | platform_security_for_java | — | — |
| oracle | platform_security_for_java | — | — |
CVSS provenance
nvdv3.07.6HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cpr5-2h98-5m4q: Unspecified vulnerability in the Oracle Platform Security for Java component in Oracle Fusion Middleware 12
ghsa_unreviewed·2022-05-17·CVSS 7.6
CVE-2016-5536 [HIGH] CWE-284 GHSA-cpr5-2h98-5m4q: Unspecified vulnerability in the Oracle Platform Security for Java component in Oracle Fusion Middleware 12
Unspecified vulnerability in the Oracle Platform Security for Java component in Oracle Fusion Middleware 12.1.3.0.0, 12.2.1.0.0, and 12.2.1.1.0 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2016-8281.
GHSA
GHSA-g5j9-qj8v-w5r9: Unspecified vulnerability in the Oracle Platform Security for Java component in Oracle Fusion Middleware 12
ghsa_unreviewed·2022-05-17·CVSS 7.6
CVE-2016-8281 [HIGH] CWE-284 GHSA-g5j9-qj8v-w5r9: Unspecified vulnerability in the Oracle Platform Security for Java component in Oracle Fusion Middleware 12
Unspecified vulnerability in the Oracle Platform Security for Java component in Oracle Fusion Middleware 12.1.3.0.0, 12.2.1.0.0, and 12.2.1.1.0 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2016-5536.
Kernel
sysctl: Drop reference added by grab_header in proc_sys_readdir
kernel_security·2017-01-06·CVSS 5.5
CVE-2016-9191 [MEDIUM] sysctl: Drop reference added by grab_header in proc_sys_readdir
sysctl: Drop reference added by grab_header in proc_sys_readdir
Fixes CVE-2016-9191, proc_sys_readdir doesn't drop reference
added by grab_header when return from !dir_emit_dots path.
It can cause any path called unregister_sysctl_table will
wait forever.
The calltrace of CVE-2016-9191:
[ 5535.960522] Call Trace:
[ 5535.963265] [] schedule+0x3f/0xa0
[ 5535.968817] [] schedule_timeout+0x3db/0x6f0
[ 5535.975346] [] ? wait_for_completion+0x45/0x130
[ 5535.982256] [] wait_for_completion+0xc3/0x130
[ 5535.988972] [] ? wake_up_q+0x80/0x80
[ 5535.994804] [] drop_sysctl_table+0xc4/0xe0
[ 5536.001227] [] drop_sysctl_table+0x77/0xe0
[ 5536.007648] [] unregister_sysctl_table+0x4d/0xa0
[ 5536.014654] [] unregister_sysctl_table+0x7f/0xa0
[ 5536.021657] [] unregister_sched_domain_sysctl+0x15/0x40
[ 5
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.securityfocus.com/bid/93772http://www.securitytracker.com/id/1037051http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.securityfocus.com/bid/93772http://www.securitytracker.com/id/1037051
2016-10-25
Published