CVE-2016-8328
published 2017-01-27CVE-2016-8328: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java Mission Control). The supported version that is affected is Java SE: 8u112…
PriorityP414low3.7CVSS 3.0
AVNACHPRNUINSUCNILAN
EPSS
1.70%
74.5th percentile
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java Mission Control). The supported version that is affected is Java SE: 8u112. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data. Note: Applies to Java Mission Control Installation. CVSS v3.0 Base Score 3.7 (Integrity impacts).
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjdk-8 | — | — |
| msrc | microsoft_hpc_pack_2019 | — | — |
| oracle | java_se | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
CVSS provenance
nvdv3.03.7LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_msrc9.8CRITICAL
vendor_debian3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vv9q-q5qm-v3xg: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java Mission Control)
ghsa_unreviewed·2022-05-14
CVE-2016-8328 [MEDIUM] GHSA-vv9q-q5qm-v3xg: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java Mission Control)
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java Mission Control). The supported version that is affected is Java SE: 8u112. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data. Note: Applies to Java Mission Control Installation. CVSS v3.0 Base Score 3.7 (Integrity impacts).
Microsoft
Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability
vendor_msrc·2025-09-09·CVSS 9.8
CVE-2025-55232 [CRITICAL] CWE-502 Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability
Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability
Description: Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network.
FAQ: What do customers need to do to mitigate this vulnerability?
If you are currently using HPC Pack 2019 Update 2, you need to upgrade to HPC Pack 2019 Update 3 (Build 6.3.8328) and then apply the QFE patch (Build 6.3.8352).
If you are currently using HPC Pack 2016, you must migrate to 2019 to receive a fix, as there is no in-place update from 2016 to 2019.
FAQ: How could an attacker exploit the vulnerability?
An attacker who successfully exploits this vulnerability could achieve remote code execution without user interaction.
Microsoft High Perf
Red Hat
JDK: unspecified vulnerability fixed in 8u121 (Java Mission Control)
vendor_redhat·2017-01-17·CVSS 3.7
CVE-2016-8328 [LOW] JDK: unspecified vulnerability fixed in 8u121 (Java Mission Control)
JDK: unspecified vulnerability fixed in 8u121 (Java Mission Control)
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java Mission Control). The supported version that is affected is Java SE: 8u112. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data. Note: Applies to Java Mission Control Installation. CVSS v3.0 Base Score 3.7 (Integrity impacts).
Debian
CVE-2016-8328: openjdk-8 - Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java Mis...
vendor_debian·2016·CVSS 3.7
CVE-2016-8328 [LOW] CVE-2016-8328: openjdk-8 - Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java Mis...
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java Mission Control). The supported version that is affected is Java SE: 8u112. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data. Note: Applies to Java Mission Control Installation. CVSS v3.0 Base Score 3.7 (Integrity impacts).
Scope: local
sid: resolved
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2017-0175.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.htmlhttp://www.securityfocus.com/bid/95581http://www.securitytracker.com/id/1037637https://security.gentoo.org/glsa/201701-65https://security.netapp.com/advisory/ntap-20170119-0001/http://rhn.redhat.com/errata/RHSA-2017-0175.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.htmlhttp://www.securityfocus.com/bid/95581http://www.securitytracker.com/id/1037637https://security.gentoo.org/glsa/201701-65https://security.netapp.com/advisory/ntap-20170119-0001/
2017-01-27
Published