First published: Mon Apr 18 2016(Updated: )
Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Management Extensions (JMX). This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service.
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.7.0-oracle-1:1.7.0.101-1jpp.1.el5_11 | 1.7.0-oracle-1:1.7.0.101-1jpp.1.el5_11 |
redhat/java | <1.6.0-sun-1:1.6.0.115-1jpp.1.el5_11 | 1.6.0-sun-1:1.6.0.115-1jpp.1.el5_11 |
redhat/java | <1.8.0-oracle-1:1.8.0.91-1jpp.1.el6_7 | 1.8.0-oracle-1:1.8.0.91-1jpp.1.el6_7 |
redhat/java | <1.7.0-oracle-1:1.7.0.101-1jpp.1.el6_7 | 1.7.0-oracle-1:1.7.0.101-1jpp.1.el6_7 |
redhat/java | <1.6.0-sun-1:1.6.0.115-1jpp.1.el6_7 | 1.6.0-sun-1:1.6.0.115-1jpp.1.el6_7 |
redhat/java | <1.8.0-oracle-1:1.8.0.91-1jpp.1.el7 | 1.8.0-oracle-1:1.8.0.91-1jpp.1.el7 |
redhat/java | <1.7.0-oracle-1:1.7.0.101-1jpp.1.el7 | 1.7.0-oracle-1:1.7.0.101-1jpp.1.el7 |
redhat/java | <1.6.0-sun-1:1.6.0.115-1jpp.1.el7 | 1.6.0-sun-1:1.6.0.115-1jpp.1.el7 |
redhat/java | <1.7.0-openjdk-1:1.7.0.101-2.6.6.1.el5_11 | 1.7.0-openjdk-1:1.7.0.101-2.6.6.1.el5_11 |
redhat/java | <1.6.0-openjdk-1:1.6.0.39-1.13.11.0.el5_11 | 1.6.0-openjdk-1:1.6.0.39-1.13.11.0.el5_11 |
redhat/java | <1.7.0-ibm-1:1.7.0.9.40-1jpp.1.el5 | 1.7.0-ibm-1:1.7.0.9.40-1jpp.1.el5 |
redhat/java | <1.6.0-ibm-1:1.6.0.16.25-1jpp.1.el5 | 1.6.0-ibm-1:1.6.0.16.25-1jpp.1.el5 |
redhat/java | <1.8.0-openjdk-1:1.8.0.91-0.b14.el6_7 | 1.8.0-openjdk-1:1.8.0.91-0.b14.el6_7 |
redhat/java | <1.7.0-openjdk-1:1.7.0.101-2.6.6.1.el6_7 | 1.7.0-openjdk-1:1.7.0.101-2.6.6.1.el6_7 |
redhat/java | <1.6.0-openjdk-1:1.6.0.39-1.13.11.0.el6_7 | 1.6.0-openjdk-1:1.6.0.39-1.13.11.0.el6_7 |
redhat/java | <1.7.1-ibm-1:1.7.1.3.40-1jpp.1.el6_7 | 1.7.1-ibm-1:1.7.1.3.40-1jpp.1.el6_7 |
redhat/java | <1.6.0-ibm-1:1.6.0.16.25-1jpp.1.el6_7 | 1.6.0-ibm-1:1.6.0.16.25-1jpp.1.el6_7 |
redhat/java | <1.8.0-ibm-1:1.8.0.3.0-1jpp.1.el6 | 1.8.0-ibm-1:1.8.0.3.0-1jpp.1.el6 |
redhat/java | <1.8.0-openjdk-1:1.8.0.91-0.b14.el7_2 | 1.8.0-openjdk-1:1.8.0.91-0.b14.el7_2 |
redhat/java | <1.7.0-openjdk-1:1.7.0.101-2.6.6.1.el7_2 | 1.7.0-openjdk-1:1.7.0.101-2.6.6.1.el7_2 |
redhat/java | <1.6.0-openjdk-1:1.6.0.39-1.13.11.0.el7_2 | 1.6.0-openjdk-1:1.6.0.39-1.13.11.0.el7_2 |
redhat/java | <1.7.1-ibm-1:1.7.1.3.40-1jpp.1.el7 | 1.7.1-ibm-1:1.7.1.3.40-1jpp.1.el7 |
redhat/java | <1.8.0-ibm-1:1.8.0.3.0-1jpp.1.el7 | 1.8.0-ibm-1:1.8.0.3.0-1jpp.1.el7 |
redhat/spacewalk-java | <0:2.0.2-109.el6 | 0:2.0.2-109.el6 |
redhat/java | <1.7.1-ibm-1:1.7.1.4.1-1jpp.1.el6_8 | 1.7.1-ibm-1:1.7.1.4.1-1jpp.1.el6_8 |
redhat/spacewalk-java | <0:2.3.8-146.el6 | 0:2.3.8-146.el6 |
Oracle Java SE and JRockit | ||
Oracle JDK 6 | =1.6.0-update113 | |
Oracle JDK 6 | =1.7.0-update99 | |
Oracle JDK 6 | =1.8.0-update77 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update113 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update99 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update77 | |
BEA JRockit | =r28.3.9 | |
debian/openjdk-8 | 8u442-ga-2 | |
Oracle Linux | =5 | |
Oracle Linux | =6 | |
Oracle Linux | =7 | |
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =15.10 | |
Ubuntu | =16.04 | |
Debian | =8.0 | |
NetApp E-Series SANtricity Management Plug-ins for VMware vCenter | ||
netapp e-series santricity storage manager | ||
netapp e-series santricity Web services Web services proxy | ||
NetApp OnCommand Balance | ||
NetApp OnCommand Cloud Manager | ||
NetApp OnCommand Insight | ||
NetApp OnCommand Performance Manager | ||
NetApp OnCommand Report | ||
NetApp OnCommand Shift | ||
NetApp OnCommand Unified Manager for 7-Mode | ||
NetApp OnCommand Unified Manager | ||
NetApp OnCommand Workflow Automation | ||
netapp storagegrid | <=9.0.4 | |
NetApp VASA Provider | >=7.2 | |
NetApp Virtual Storage Console for VMware vSphere | >=7.2 | |
Apache Cassandra | >=2.1.0<2.1.22 | |
Apache Cassandra | >=2.2.0<2.2.18 | |
Apache Cassandra | >=3.0.0<3.0.22 | |
Apache Cassandra | >=3.11.0<3.11.8 | |
Apache Cassandra | =4.0.0-beta1 | |
redhat satellite | =5.6 | |
redhat satellite | =5.7 | |
redhat enterprise Linux desktop | =5.0 | |
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux desktop | =7.0 | |
redhat enterprise Linux eus | =6.7 | |
redhat enterprise Linux eus | =7.2 | |
redhat enterprise Linux eus | =7.3 | |
redhat enterprise Linux eus | =7.4 | |
redhat enterprise Linux eus | =7.5 | |
redhat enterprise Linux eus | =7.6 | |
redhat enterprise Linux eus | =7.7 | |
redhat enterprise Linux server | =5.0 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux server | =7.0 | |
redhat enterprise Linux server aus | =7.2 | |
redhat enterprise Linux server aus | =7.3 | |
redhat enterprise Linux server aus | =7.4 | |
redhat enterprise Linux server aus | =7.6 | |
redhat enterprise Linux server aus | =7.7 | |
redhat enterprise Linux server eus | =6.7 | |
redhat enterprise Linux server eus | =7.2 | |
redhat enterprise Linux server tus | =7.2 | |
redhat enterprise Linux server tus | =7.3 | |
redhat enterprise Linux server tus | =7.6 | |
redhat enterprise Linux server tus | =7.7 | |
redhat enterprise Linux workstation | =5.0 | |
redhat enterprise Linux workstation | =6.0 | |
redhat enterprise Linux workstation | =7.0 | |
SUSE Linux Enterprise Module for Legacy | =12 | |
SUSE Manager | =2.1 | |
suse manager proxy | =2.1 | |
openSUSE OpenStack Cloud | =5 | |
openSUSE | =42.1 | |
openSUSE | =13.1 | |
openSUSE | =13.2 | |
SUSE Linux Enterprise Desktop with Beagle | =12 | |
SUSE Linux Enterprise Desktop with Beagle | =12-sp1 | |
SUSE Linux Enterprise Server | =10-sp4 | |
SUSE Linux Enterprise Server | =11-sp2 | |
SUSE Linux Enterprise Server | =11-sp3 | |
SUSE Linux Enterprise Server | =11-sp4 | |
SUSE Linux Enterprise Server | =12 | |
SUSE Linux Enterprise Server | =12-sp1 | |
SUSE Linux Enterprise Software Development Kit | =11-sp4 | |
SUSE Linux Enterprise Software Development Kit | =12-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2016-3427 is classified as a critical vulnerability due to its potential impact on confidentiality, integrity, and availability.
To fix CVE-2016-3427, update to the latest recommended Java version as per the vendor's security advisories.
CVE-2016-3427 affects multiple Java versions including Oracle JDK 6, 7, and 8, along with JRockit.
Yes, CVE-2016-3427 can be exploited by remote attackers through vulnerabilities related to Java Management Extensions (JMX).
CVE-2016-3427 is classified as a denial of service vulnerability that can lead to various security impacts.