Severity
5.9MEDIUMNVD
OSV3.1
EPSS
1.9%
top 16.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 25
Latest updateOct 29

Description

Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality via vectors related to Networking.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

NVDoracle/jdk1.6.0, 1.7.0, 1.8.0+2
NVDoracle/jre1.6.0, 1.7.0, 1.8.0+2

Patches

🔴Vulnerability Details

7
OSV
Jenkins Eggplant Runner Plugin protection mechanism disabled2025-10-29
GHSA
Jenkins Eggplant Runner Plugin protection mechanism disabled2025-10-29
GHSA
GHSA-6q5r-8qc5-j49x: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality via vect2022-05-13
OSV
openjdk-7 vulnerabilities2016-11-17
OSV
openjdk-8 vulnerabilities2016-11-03

📋Vendor Advisories

6
Jenkins
Jenkins Security Advisory 2025-10-292025-10-29
Ubuntu
OpenJDK 6 vulnerabilities2016-12-08
Ubuntu
OpenJDK 7 vulnerabilities2016-11-17
Ubuntu
OpenJDK 8 vulnerabilities2016-11-03
Red Hat
OpenJDK: exposure of server authentication credentials to proxy (Networking, 8160838)2016-10-18

💬Community

1
Bugzilla
CVE-2016-5597 OpenJDK: exposure of server authentication credentials to proxy (Networking, 8160838)2016-10-18
CVE-2016-5597 — Sensitive Information Exposure | cvebase