First published: Tue Apr 19 2016(Updated: )
Oracle Java SE 6u115, 7u101 and 8u91 fixes an unspecified vulnerability in the Deployment component (<a href="https://access.redhat.com/security/cve/CVE-2016-3449">CVE-2016-3449</a>). Upstream has CVSSv2 scored this issue as: 7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C External Reference: <a href="http://www.oracle.com/technetwork/topics/security/cpuapr2016-2881694.html#AppendixJAVA">http://www.oracle.com/technetwork/topics/security/cpuapr2016-2881694.html#AppendixJAVA</a>
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.7.0-oracle-1:1.7.0.101-1jpp.1.el5_11 | 1.7.0-oracle-1:1.7.0.101-1jpp.1.el5_11 |
redhat/java | <1.6.0-sun-1:1.6.0.115-1jpp.1.el5_11 | 1.6.0-sun-1:1.6.0.115-1jpp.1.el5_11 |
redhat/java | <1.8.0-oracle-1:1.8.0.91-1jpp.1.el6_7 | 1.8.0-oracle-1:1.8.0.91-1jpp.1.el6_7 |
redhat/java | <1.7.0-oracle-1:1.7.0.101-1jpp.1.el6_7 | 1.7.0-oracle-1:1.7.0.101-1jpp.1.el6_7 |
redhat/java | <1.6.0-sun-1:1.6.0.115-1jpp.1.el6_7 | 1.6.0-sun-1:1.6.0.115-1jpp.1.el6_7 |
redhat/java | <1.8.0-oracle-1:1.8.0.91-1jpp.1.el7 | 1.8.0-oracle-1:1.8.0.91-1jpp.1.el7 |
redhat/java | <1.7.0-oracle-1:1.7.0.101-1jpp.1.el7 | 1.7.0-oracle-1:1.7.0.101-1jpp.1.el7 |
redhat/java | <1.6.0-sun-1:1.6.0.115-1jpp.1.el7 | 1.6.0-sun-1:1.6.0.115-1jpp.1.el7 |
redhat/java | <1.7.0-ibm-1:1.7.0.9.40-1jpp.1.el5 | 1.7.0-ibm-1:1.7.0.9.40-1jpp.1.el5 |
redhat/java | <1.6.0-ibm-1:1.6.0.16.25-1jpp.1.el5 | 1.6.0-ibm-1:1.6.0.16.25-1jpp.1.el5 |
redhat/java | <1.7.1-ibm-1:1.7.1.3.40-1jpp.1.el6_7 | 1.7.1-ibm-1:1.7.1.3.40-1jpp.1.el6_7 |
redhat/java | <1.6.0-ibm-1:1.6.0.16.25-1jpp.1.el6_7 | 1.6.0-ibm-1:1.6.0.16.25-1jpp.1.el6_7 |
redhat/java | <1.8.0-ibm-1:1.8.0.3.0-1jpp.1.el6 | 1.8.0-ibm-1:1.8.0.3.0-1jpp.1.el6 |
redhat/java | <1.7.1-ibm-1:1.7.1.3.40-1jpp.1.el7 | 1.7.1-ibm-1:1.7.1.3.40-1jpp.1.el7 |
redhat/java | <1.8.0-ibm-1:1.8.0.3.0-1jpp.1.el7 | 1.8.0-ibm-1:1.8.0.3.0-1jpp.1.el7 |
redhat/spacewalk-java | <0:2.0.2-109.el6 | 0:2.0.2-109.el6 |
redhat/java | <1.7.1-ibm-1:1.7.1.4.1-1jpp.1.el6_8 | 1.7.1-ibm-1:1.7.1.4.1-1jpp.1.el6_8 |
redhat/spacewalk-java | <0:2.3.8-146.el6 | 0:2.3.8-146.el6 |
Oracle JDK 6 | =1.6.0-update113 | |
Oracle JDK 6 | =1.7.0-update99 | |
Oracle JDK 6 | =1.8.0-update77 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update113 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update99 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update77 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2016-3449 has been assigned a CVSSv2 score of 7.6, indicating high severity due to its potential impact on confidentiality, integrity, and availability.
To remediate CVE-2016-3449, update to the latest patched versions of Oracle Java SE, specifically 6u115, 7u101, or 8u91.
CVE-2016-3449 affects Oracle Java SE versions 6u115, 7u101, and 8u91.
Yes, CVE-2016-3449 is an unspecified vulnerability found in the Deployment component of Oracle Java.
You can verify your Java installation version against the known affected versions: Oracle Java SE 6u115, 7u101, or 8u91.