CVE-2016-5597 — Sensitive Information Exposure in Oracle JDK
Severity
5.9MEDIUMNVD
OSV3.1
EPSS
1.9%
top 16.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 25
Latest updateOct 29
Description
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality via vectors related to Networking.
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6
Affected Packages2 packages
Patches
🔴Vulnerability Details
7GHSA▶
GHSA-6q5r-8qc5-j49x: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality via vect↗2022-05-13
📋Vendor Advisories
6💬Community
1Bugzilla▶
CVE-2016-5597 OpenJDK: exposure of server authentication credentials to proxy (Networking, 8160838)↗2016-10-18