Lucene search

K
f5F5F5:K05016441
HistorySep 07, 2016 - 12:00 a.m.

K05016441 : Oracle Java vulnerability CVE-2016-3508

2016-09-0700:00:00
my.f5.com
26

AI Score

6.5

Confidence

Low

EPSS

0.011

Percentile

84.9%

Security Advisory Description

Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; Java SE Embedded 8u91; and JRockit R28.3.10 allows remote attackers to affect availability via vectors related to JAXP, a different vulnerability than CVE-2016-3500. (CVE-2016-3508)
Impact
An attacker that uses specially crafted XML files can cause a Java application, using JAXP, to consume excessive amounts of memory and CPU time when parsed if the system is configured to load and process XML documents from untrusted sources.