Lucene search

K
nessusTenable9448.PRM
HistoryAug 08, 2016 - 12:00 a.m.

Oracle Java SE 6 < Update 115 / 7 < Update 101 / 8 < Update 92 Multiple Vulnerabilities

2016-08-0800:00:00
Tenable
www.tenable.com
16

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.495

Percentile

97.5%

The version of Oracle Java SE installed on the remote host is prior to 6 Update 115, 7 Update 101, or 8 Update 92 and is affected by multiple vulnerabilities :

  • An unspecified flaw related to the ‘Serialization’ subcomponent may allow a context-dependent attacker to execute arbitrary code. (CVE-2016-0686)
  • An unspecified flaw related to the ‘Hotspot’ subcomponent may allow a context-dependent attacker to execute arbitrary code. (CVE-2016-0687)
  • An unspecified flaw related to the ‘Security’ subcomponent may allow a remote attacker to gain access to potentially sensitive information. (CVE-2016-0695)
  • An unspecified flaw related to the ‘2D’ subcomponent may allow a context-dependent attacker to cause a denial of service. (CVE-2016-3422)
  • An unspecified flaw related to the ‘JAXP’ subcomponent may allow a remote attacker to cause a denial of service. (CVE-2016-3425)
  • An unspecified flaw related to the ‘JCE’ subcomponent may allow a context-dependent attacker to gain access to potentially sensitive information. (CVE-2016-3426)
  • A flaw related to the ‘JMX’ subcomponent may allow a remote attacker to execute arbitrary code through Java deserialization. (CVE-2016-3427)
  • An out-of-bounds read flaw within the ‘2D’ subcomponent is triggered when handling specially crafted files. This may allow a context-dependent attacker gain unauthorized access to potentially sensitive information. (CVE-2016-3443)
  • An unspecified flaw related to the ‘Deployment’ subcomponent may allow a context-dependent attacker to execute arbitrary code. (CVE-2016-3449)
Binary data 9448.prm

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.495

Percentile

97.5%