CVE-2016-8328: Low severity Oracle JDK vulnerability
Oracle Java SE 8u121 fixes an unspecified vulnerability in the Java Mission Control component (CVE-2016-8328). Upstream has CVSS scored this issue as: 3.7/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
External Reference:
http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html#AppendixJAVA
Other sources
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java Mission Control). The supported version that is affected is Java SE: 8u112. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data. Note: Applies to Java Mission Control Installation. CVSS v3.0 Base Score 3.7 (Integrity impacts).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8328?
CVE-2016-8328 has a CVSS score of 3.7, indicating a low severity vulnerability.
How do I fix CVE-2016-8328?
To fix CVE-2016-8328, update to Oracle Java SE version 8u121 or later.
Which software is affected by CVE-2016-8328?
CVE-2016-8328 affects Oracle Java SE versions prior to 8u121.
Is there a workaround for CVE-2016-8328?
No specific workaround is recommended for CVE-2016-8328; updating Java is advised.
What components are involved in CVE-2016-8328?
CVE-2016-8328 involves an unspecified vulnerability in the Java Mission Control component.