VDB
CVE-2016-8328
CVE-2016-8328
PUBLISHED
CVSS 3.700000047683716 LOW
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java Mission Control). The supported version that is affected is Java SE: 8u112. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data. Note: Applies to Java Mission Control Installation. CVSS v3.0 Base Score 3.7 (Integrity impacts).
EPSS 0.56% · 68.6th percentile
Risk Scores
CVSS 3.0
3.700000047683716
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS Score
0.56%
68.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| oracle | jdk | 1.8 |
| Oracle | Java SE | 8u112 |
| oracle | jre | 1.8 |
Exploit Intelligence
- scopion/CVE-2017-3241 (github-poc)
- scopion/CVE-2017-3241 (github-poc)
- scopion/CVE-2017-3241 (github-poc)
- scopion/CVE-2017-3241 (github-poc)
- POC for java RMI deserialization vulnerability (github-poc)
- POC for java RMI deserialization vulnerability (github-poc)
- POC for java RMI deserialization vulnerability (github-poc)
- POC for java RMI deserialization vulnerability (github-poc)
- Simplified Version of Cryptography Attack based on Birthday Paradox: Sweet32 (CVE-2016-2183) (github-poc)
- Simplified Version of Cryptography Attack based on Birthday Paradox: Sweet32 (CVE-2016-2183) (github-poc)
…and 10 more exploits
Timeline
- Jan 18, 2017 CVE Published
- Jan 19, 2017 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- http://www.securityfocus.com/bid/95581 url
- http://www.securitytracker.com/id/1037637 url
- GLSA-201701-65 vendor-advisory
- RHSA-2017:0175 vendor-advisory
- https://security.netapp.com/advisory/ntap-20170119-0001/ url
- http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html url
- https://nvd.nist.gov/vuln/detail/CVE-2016-8328 advisory
- https://security.netapp.com/advisory/ntap-20170119-0001 url