CVE-2016-5542Use of a Broken or Risky Cryptographic Algorithm in Oracle JDK

Severity
3.1LOWNVD
EPSS
2.0%
top 16.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 25
Latest updateMay 13

Description

Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors related to Libraries.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 1.6 | Impact: 1.4

Affected Packages2 packages

NVDoracle/jdk1.6.0, 1.7.0, 1.8.0+2
NVDoracle/jre1.6.0, 1.7.0, 1.8.0+2

Patches

🔴Vulnerability Details

5
GHSA
GHSA-gjxp-f524-fgrv: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors re2022-05-13
OSV
openjdk-7 vulnerabilities2016-11-17
OSV
openjdk-8 vulnerabilities2016-11-03
CVEList
CVE-2016-5542: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors re2016-10-25
OSV
CVE-2016-5542: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors re2016-10-25

📋Vendor Advisories

5
Ubuntu
OpenJDK 6 vulnerabilities2016-12-08
Ubuntu
OpenJDK 7 vulnerabilities2016-11-17
Ubuntu
OpenJDK 8 vulnerabilities2016-11-03
Red Hat
OpenJDK: missing algorithm restrictions for jar verification (Libraries, 8155973)2016-10-18
Debian
CVE-2016-5542: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Emb...2016

💬Community

2
Bugzilla
CVE-2017-3539 OpenJDK: MD5 allowed for jar verification (Security, 8171121)2017-04-18
Bugzilla
CVE-2016-5542 OpenJDK: missing algorithm restrictions for jar verification (Libraries, 8155973)2016-10-17
CVE-2016-5542 — Oracle JDK vulnerability | cvebase