CVE-2016-3427: Oracle Java SE and JRockit Unspecified Vulnerability
It was discovered that the RMI (Java Remote Method Invocation) server implementation in the JMX (Java Management Extensions) component of OpenJDK did not restrict which classes can be deserialized when deserializing authentication credentials. A remote unauthenticated attacker able to connect to a JMX port could possibly use this flaw trigger deserialization flaws.
Other sources
It was discovered that the RMI server implementation in the JMX component in OpenJDK did not restrict which classes can be deserialized when deserializing authentication credentials. A remote, unauthenticated attacker able to connect to a JMX port could possibly use this flaw to trigger deserialization flaws.
Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Management Extensions (JMX). This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service.
— CISA
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Jav ...
— Debian
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-oracle-1:1.7.0.101-1jpp.1.el5_11 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-sun-1:1.6.0.115-1jpp.1.el5_11 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-oracle-1:1.8.0.91-1jpp.1.el6_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-oracle-1:1.7.0.101-1jpp.1.el6_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-sun-1:1.6.0.115-1jpp.1.el6_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-oracle-1:1.8.0.91-1jpp.1.el7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-oracle-1:1.7.0.101-1jpp.1.el7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-sun-1:1.6.0.115-1jpp.1.el7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-openjdk-1:1.7.0.101-2.6.6.1.el5_11 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-openjdk-1:1.6.0.39-1.13.11.0.el5_11 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-ibm-1:1.7.0.9.40-1jpp.1.el5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-ibm-1:1.6.0.16.25-1jpp.1.el5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-openjdk-1:1.8.0.91-0.b14.el6_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-openjdk-1:1.7.0.101-2.6.6.1.el6_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-openjdk-1:1.6.0.39-1.13.11.0.el6_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.1-ibm-1:1.7.1.3.40-1jpp.1.el6_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-ibm-1:1.6.0.16.25-1jpp.1.el6_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-ibm-1:1.8.0.3.0-1jpp.1.el6 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-openjdk-1:1.8.0.91-0.b14.el7_2 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-openjdk-1:1.7.0.101-2.6.6.1.el7_2 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-openjdk-1:1.6.0.39-1.13.11.0.el7_2 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.1-ibm-1:1.7.1.3.40-1jpp.1.el7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-ibm-1:1.8.0.3.0-1jpp.1.el7 - Upgrade
Upgrade
redhat/spacewalk-javato a version that resolves this vulnerability.Fixed in 0:2.0.2-109.el6 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.1-ibm-1:1.7.1.4.1-1jpp.1.el6_8 - Upgrade
Upgrade
redhat/spacewalk-javato a version that resolves this vulnerability.Fixed in 0:2.3.8-146.el6 - Upgrade
Upgrade
debian/openjdk-8to a version that resolves this vulnerability.Fixed in 8u442-ga-2
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2016-3427?
CVE-2016-3427 is classified as a critical vulnerability due to its potential impact on confidentiality, integrity, and availability.
How do I fix CVE-2016-3427?
To fix CVE-2016-3427, update to the latest recommended Java version as per the vendor's security advisories.
Which versions of Java are affected by CVE-2016-3427?
CVE-2016-3427 affects multiple Java versions including Oracle JDK 6, 7, and 8, along with JRockit.
Can CVE-2016-3427 be exploited remotely?
Yes, CVE-2016-3427 can be exploited by remote attackers through vulnerabilities related to Java Management Extensions (JMX).
What type of vulnerability is CVE-2016-3427 classified as?
CVE-2016-3427 is classified as a denial of service vulnerability that can lead to various security impacts.