CVE-2016-5554
published 2016-10-25CVE-2016-5554: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors related to…
PriorityP423medium4.3CVSS 3.0
AVNACLPRNUIRSUCNILAN
EPSS
3.10%
86.3th percentile
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors related to JMX.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjdk-8 | < openjdk-8 8u111-b14-1 (sid) | openjdk-8 8u111-b14-1 (sid) |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6cr3-4q7p-67qc: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors re
ghsa_unreviewed·2022-05-13
CVE-2016-5554 [MEDIUM] GHSA-6cr3-4q7p-67qc: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors re
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors related to JMX.
OSV
openjdk-7 vulnerabilities
osv·2016-11-17·CVSS 3.1
CVE-2016-5542 [LOW] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK did not properly
check received Java Debug Wire Protocol (JDWP) packets. An attacker could
use this to send debugging commands to a Java application with debugging
enabled. (CVE-2016-5573)
It was discovered that the Hotspot component of OpenJDK did not properly
check arguments of the Sys
OSV
openjdk-8 vulnerabilities
osv·2016-11-03·CVSS 3.1
CVE-2016-5582 [LOW] openjdk-8 vulnerabilities
openjdk-8 vulnerabilities
It was discovered that the Hotspot component of OpenJDK did not properly
check arguments of the System.arraycopy() function in certain cases. An
attacker could use this to bypass Java sandbox restrictions.
(CVE-2016-5582)
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK did not properly
check received Java Debug Wire Protocol (JDWP) pa
OSV
CVE-2016-5554: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors re
osv·2016-10-25·CVSS 4.3
CVE-2016-5554 [MEDIUM] CVE-2016-5554: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors re
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors related to JMX.
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2016-12-08·CVSS 3.1
CVE-2016-5542 [LOW] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK did not properly
check received Java Debug Wire Protocol (JDWP) packets. An attacker could
use this to send debugging commands to a Java application with debugging
enabled. (CVE-2016-5573)
It was discovered that the Hotspo
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2016-11-17·CVSS 3.1
CVE-2016-5542 [LOW] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK did not properly
check received Java Debug Wire Protocol (JDWP) packets. An attacker could
use this to send debugging commands to a Java application with debugging
enabled. (CVE-2016-5573)
It was discovered that the Hotspo
Ubuntu
OpenJDK 8 vulnerabilities
vendor_ubuntu·2016-11-03·CVSS 3.1
CVE-2016-5542 [LOW] OpenJDK 8 vulnerabilities
Title: OpenJDK 8 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 8.
It was discovered that the Hotspot component of OpenJDK did not properly
check arguments of the System.arraycopy() function in certain cases. An
attacker could use this to bypass Java sandbox restrictions.
(CVE-2016-5582)
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK
Red Hat
OpenJDK: insufficient classloader consistency checks in ClassLoaderWithRepository (JMX, 8157739)
vendor_redhat·2016-10-18·CVSS 4.3
CVE-2016-5554 [MEDIUM] OpenJDK: insufficient classloader consistency checks in ClassLoaderWithRepository (JMX, 8157739)
OpenJDK: insufficient classloader consistency checks in ClassLoaderWithRepository (JMX, 8157739)
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors related to JMX.
A flaw was found in the way the JMX component of OpenJDK handled classloaders. An untrusted Java application or applet could use this flaw to bypass certain Java sandbox restrictions.
Debian
CVE-2016-5554: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Emb...
vendor_debian·2016·CVSS 4.3
CVE-2016-5554 [MEDIUM] CVE-2016-5554: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Emb...
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors related to JMX.
Scope: local
sid: resolved (fixed in 8u111-b14-1)
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2016-2079.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2088.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2089.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2090.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2136.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2137.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2138.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2658.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2659.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0061.htmlhttp://www.debian.org/security/2016/dsa-3707http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.securityfocus.com/bid/93637http://www.securitytracker.com/id/1037040http://www.ubuntu.com/usn/USN-3130-1http://www.ubuntu.com/usn/USN-3154-1https://access.redhat.com/errata/RHSA-2017:1216https://security.gentoo.org/glsa/201611-04https://security.gentoo.org/glsa/201701-43https://security.netapp.com/advisory/ntap-20161019-0001/http://rhn.redhat.com/errata/RHSA-2016-2079.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2088.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2089.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2090.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2136.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2137.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2138.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2658.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2659.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0061.htmlhttp://www.debian.org/security/2016/dsa-3707http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.securityfocus.com/bid/93637http://www.securitytracker.com/id/1037040http://www.ubuntu.com/usn/USN-3130-1http://www.ubuntu.com/usn/USN-3154-1https://access.redhat.com/errata/RHSA-2017:1216https://security.gentoo.org/glsa/201611-04https://security.gentoo.org/glsa/201701-43https://security.netapp.com/advisory/ntap-20161019-0001/
2016-10-25
Published