CVE-2016-5597
published 2016-10-25CVE-2016-5597: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality via vectors…
PriorityP433medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
3.94%
89.2th percentile
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality via vectors related to Networking.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjdk-8 | < openjdk-8 8u111-b14-1 (sid) | openjdk-8 8u111-b14-1 (sid) |
| jenkins | azure_cli_plugin | — | — |
| jenkins | byteguard_build_actions_plugin | — | — |
| jenkins | curseforge_publisher_plugin | — | — |
| jenkins | eggplant_runner_plugin | — | — |
| jenkins | extensible_choice_parameter_plugin | — | — |
| jenkins | jdepend_maven_plugin | — | — |
| jenkins | jdepend_plugin | — | — |
| jenkins | mcp_server_plugin | — | — |
| jenkins | nexus_task_runner_plugin | — | — |
| jenkins | openshift_pipeline_plugin | — | — |
| jenkins | publish_to_bitbucket_plugin | — | — |
| jenkins | saml_plugin | — | — |
| jenkins | start_windocks_containers_plugin | — | — |
| jenkins | themis_plugin | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
ghsa5.9MEDIUM
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Jenkins Eggplant Runner Plugin protection mechanism disabled
osv·2025-10-29·CVSS 5.9
CVE-2025-64135 [MEDIUM] Jenkins Eggplant Runner Plugin protection mechanism disabled
Jenkins Eggplant Runner Plugin protection mechanism disabled
Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property `jdk.http.auth.tunneling.disabledSchemes` to an empty value as part of applying a proxy configuration.
This disables a protection mechanism of the Java runtime addressing CVE-2016-5597.
As of publication of this advisory, there is no fix.
GHSA
Jenkins Eggplant Runner Plugin protection mechanism disabled
ghsa·2025-10-29·CVSS 5.9
CVE-2025-64135 [MEDIUM] CWE-1188 Jenkins Eggplant Runner Plugin protection mechanism disabled
Jenkins Eggplant Runner Plugin protection mechanism disabled
Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property `jdk.http.auth.tunneling.disabledSchemes` to an empty value as part of applying a proxy configuration.
This disables a protection mechanism of the Java runtime addressing CVE-2016-5597.
As of publication of this advisory, there is no fix.
GHSA
GHSA-6q5r-8qc5-j49x: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality via vect
ghsa_unreviewed·2022-05-13
CVE-2016-5597 [MEDIUM] CWE-200 GHSA-6q5r-8qc5-j49x: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality via vect
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality via vectors related to Networking.
OSV
openjdk-7 vulnerabilities
osv·2016-11-17·CVSS 3.1
CVE-2016-5542 [LOW] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK did not properly
check received Java Debug Wire Protocol (JDWP) packets. An attacker could
use this to send debugging commands to a Java application with debugging
enabled. (CVE-2016-5573)
It was discovered that the Hotspot component of OpenJDK did not properly
check arguments of the Sys
OSV
openjdk-8 vulnerabilities
osv·2016-11-03·CVSS 3.1
CVE-2016-5582 [LOW] openjdk-8 vulnerabilities
openjdk-8 vulnerabilities
It was discovered that the Hotspot component of OpenJDK did not properly
check arguments of the System.arraycopy() function in certain cases. An
attacker could use this to bypass Java sandbox restrictions.
(CVE-2016-5582)
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK did not properly
check received Java Debug Wire Protocol (JDWP) pa
OSV
CVE-2016-5597: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality via vect
osv·2016-10-25·CVSS 5.9
CVE-2016-5597 [MEDIUM] CVE-2016-5597: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality via vect
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality via vectors related to Networking.
Jenkins
Jenkins Security Advisory 2025-10-29
vendor_jenkins·2025-10-29·CVSS 7.5
CVE-2016-5597 [HIGH] Jenkins Security Advisory 2025-10-29
Title: Jenkins Security Advisory 2025-10-29
Jenkins Security Advisory 2025-10-29
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Azure CLI
Plugin
ByteGuard Build Actions
Plugin
Curseforge Publisher
Plugin
Eggplant Runner
Plugin
Extensible Choice Parameter
Plugin
JDepend
Plugin
MCP Server
Plugin
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2016-12-08·CVSS 3.1
CVE-2016-5542 [LOW] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK did not properly
check received Java Debug Wire Protocol (JDWP) packets. An attacker could
use this to send debugging commands to a Java application with debugging
enabled. (CVE-2016-5573)
It was discovered that the Hotspo
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2016-11-17·CVSS 3.1
CVE-2016-5542 [LOW] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK did not properly
check received Java Debug Wire Protocol (JDWP) packets. An attacker could
use this to send debugging commands to a Java application with debugging
enabled. (CVE-2016-5573)
It was discovered that the Hotspo
Ubuntu
OpenJDK 8 vulnerabilities
vendor_ubuntu·2016-11-03·CVSS 3.1
CVE-2016-5542 [LOW] OpenJDK 8 vulnerabilities
Title: OpenJDK 8 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 8.
It was discovered that the Hotspot component of OpenJDK did not properly
check arguments of the System.arraycopy() function in certain cases. An
attacker could use this to bypass Java sandbox restrictions.
(CVE-2016-5582)
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK
Red Hat
OpenJDK: exposure of server authentication credentials to proxy (Networking, 8160838)
vendor_redhat·2016-10-18·CVSS 5.9
CVE-2016-5597 [MEDIUM] CWE-319 OpenJDK: exposure of server authentication credentials to proxy (Networking, 8160838)
OpenJDK: exposure of server authentication credentials to proxy (Networking, 8160838)
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality via vectors related to Networking.
A flaw was found in the way the Networking component of OpenJDK handled HTTP proxy authentication. A Java application could possibly expose HTTPS server authentication credentials via a plain text network connection to an HTTP proxy if proxy asked for authentication.
Debian
CVE-2016-5597: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Emb...
vendor_debian·2016·CVSS 5.9
CVE-2016-5597 [MEDIUM] CVE-2016-5597: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Emb...
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality via vectors related to Networking.
Scope: local
sid: resolved (fixed in 8u111-b14-1)
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2016-2079.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2088.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2089.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2090.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2136.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2137.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2138.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2658.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2659.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0061.htmlhttp://www.debian.org/security/2016/dsa-3707http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.securityfocus.com/bid/93636http://www.securitytracker.com/id/1037040http://www.ubuntu.com/usn/USN-3130-1http://www.ubuntu.com/usn/USN-3154-1https://access.redhat.com/errata/RHSA-2017:1216https://security.gentoo.org/glsa/201611-04https://security.gentoo.org/glsa/201701-43https://security.netapp.com/advisory/ntap-20161019-0001/http://rhn.redhat.com/errata/RHSA-2016-2079.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2088.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2089.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2090.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2136.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2137.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2138.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2658.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2659.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0061.htmlhttp://www.debian.org/security/2016/dsa-3707http://www.openwall.com/lists/oss-security/2025/10/29/2http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.securityfocus.com/bid/93636http://www.securitytracker.com/id/1037040http://www.ubuntu.com/usn/USN-3130-1http://www.ubuntu.com/usn/USN-3154-1https://access.redhat.com/errata/RHSA-2017:1216https://security.gentoo.org/glsa/201611-04https://security.gentoo.org/glsa/201701-43https://security.netapp.com/advisory/ntap-20161019-0001/
2016-10-25
Published