CVE-2016-0695

Published on: 04/21/2016 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:13 PM UTC

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Certain versions of Jdk from Oracle contain the following vulnerability:

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality via vectors related to Security.

  • CVE-2016-0695 has been assigned by URL Logo [email protected] to track the vulnerability - currently rated as MEDIUM severity.

CVSS3 Score: 5.9 - MEDIUM

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
NETWORK HIGH NONE NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED HIGH NONE NONE

CVSS2 Score: 2.6 - LOW

Access
Vector
Access
Complexity
Authentication
NETWORK HIGH NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
PARTIAL NONE NONE

CVE References

Description Tags Link
Oracle Critical Patch Update Advisory - April 2016 Vendor Advisory
www.oracle.com
text/html
URL Logo CONFIRM www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html
McAfee Security Bulletin: ePolicy Orchestrator update fixes multiple Oracle Java vulnerabilities kc.mcafee.com
text/html
URL Logo CONFIRM kc.mcafee.com/corporate/index?page=content&id=SB10159
[security-announce] openSUSE-SU-2016:1230-1: important: Security update lists.opensuse.org
text/html
URL Logo SUSE openSUSE-SU-2016:1230
USN-2964-1: OpenJDK 7 vulnerabilities | Ubuntu www.ubuntu.com
text/html
URL Logo UBUNTU USN-2964-1
[security-announce] openSUSE-SU-2016:1235-1: important: Security update lists.opensuse.org
text/html
URL Logo SUSE openSUSE-SU-2016:1235
April 2016 Java Platform Standard Edition Vulnerabilities in Multiple NetApp Products | NetApp Product Security security.netapp.com
text/html
URL Logo CONFIRM security.netapp.com/advisory/ntap-20160420-0001/
Red Hat Customer Portal web.archive.org
text/html
Inactive LinkNot Archived
URL Logo REDHAT RHSA-2016:0678
Oracle Java SE and JRockit CVE-2016-0695 Remote Security Vulnerability cve.report (archive)
text/html
URL Logo BID 86438
Debian -- Security Information -- DSA-3558-1 openjdk-7 www.debian.org
Depreciated Link
text/html
URL Logo DEBIAN DSA-3558
USN-2972-1: OpenJDK 6 vulnerabilities | Ubuntu www.ubuntu.com
text/html
URL Logo UBUNTU USN-2972-1
Red Hat Customer Portal web.archive.org
text/html
Inactive LinkNot Archived
URL Logo REDHAT RHSA-2016:0676
Red Hat Customer Portal web.archive.org
text/html
Inactive LinkNot Archived
URL Logo REDHAT RHSA-2016:0650
Red Hat Customer Portal Third Party Advisory
web.archive.org
text/html
Inactive LinkNot Archived
URL Logo REDHAT RHSA-2016:0723
[security-announce] SUSE-SU-2016:1250-1: important: Security update for lists.opensuse.org
text/html
URL Logo SUSE SUSE-SU-2016:1250
Oracle Java SE Multiple Flaws Let Remote Users Access Data and Gain Elevated Privileges on the Target System - SecurityTracker www.securitytracker.com
text/html
URL Logo SECTRACK 1035596
Oracle Linux Bulletin - April 2016 Vendor Advisory
www.oracle.com
text/html
URL Logo CONFIRM www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
Red Hat Customer Portal web.archive.org
text/html
Inactive LinkNot Archived
URL Logo REDHAT RHSA-2016:0651
[security-announce] openSUSE-SU-2016:1262-1: important: Security update lists.opensuse.org
text/html
URL Logo SUSE openSUSE-SU-2016:1262
USN-2963-1: OpenJDK 8 vulnerabilities | Ubuntu www.ubuntu.com
text/html
URL Logo UBUNTU USN-2963-1
IcedTea: Multiple vulnerabilities (GLSA 201606-18) — Gentoo security Third Party Advisory
security.gentoo.org
text/html
URL Logo GENTOO GLSA-201606-18
[security-announce] openSUSE-SU-2016:1222-1: important: Security update lists.opensuse.org
text/html
URL Logo SUSE openSUSE-SU-2016:1222
[security-announce] openSUSE-SU-2016:1265-1: important: Security update lists.opensuse.org
text/html
URL Logo SUSE openSUSE-SU-2016:1265
Red Hat Customer Portal web.archive.org
text/html
Inactive LinkNot Archived
URL Logo REDHAT RHSA-2016:0675
[security-announce] SUSE-SU-2016:1248-1: important: Security update for lists.opensuse.org
text/html
URL Logo SUSE SUSE-SU-2016:1248
Red Hat Customer Portal web.archive.org
text/html
Inactive LinkNot Archived
URL Logo REDHAT RHSA-2016:0677
Red Hat Customer Portal web.archive.org
text/html
Inactive LinkNot Archived
URL Logo REDHAT RHSA-2016:0679

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationOracleJdk1.6.0update_113AllAll
ApplicationOracleJdk1.7.0update_99AllAll
ApplicationOracleJdk1.8.0update77AllAll
ApplicationOracleJdk1.6.0update_113AllAll
ApplicationOracleJdk1.7.0update_99AllAll
ApplicationOracleJdk1.8.0update77AllAll
ApplicationOracleJre1.6.0update_113AllAll
ApplicationOracleJre1.7.0update_99AllAll
ApplicationOracleJre1.8.0update_77AllAll
ApplicationOracleJre1.6.0update_113AllAll
ApplicationOracleJre1.7.0update_99AllAll
ApplicationOracleJre1.8.0update_77AllAll
ApplicationOracleJrockitr28.3.9AllAllAll
ApplicationOracleJrockitr28.3.9AllAllAll
Operating
System
OracleLinux5.0AllAllAll
Operating
System
OracleLinux6AllAllAll
Operating
System
OracleLinux7AllAllAll
Operating
System
OracleLinux5.0AllAllAll
Operating
System
OracleLinux6AllAllAll
Operating
System
OracleLinux7AllAllAll
Operating
System
RedhatEnterprise Linux Desktop5.0AllAllAll
Operating
System
RedhatEnterprise Linux Desktop6.0AllAllAll
Operating
System
RedhatEnterprise Linux Desktop7.0AllAllAll
Operating
System
RedhatEnterprise Linux Desktop5.0AllAllAll
Operating
System
RedhatEnterprise Linux Desktop6.0AllAllAll
Operating
System
RedhatEnterprise Linux Desktop7.0AllAllAll
Operating
System
RedhatEnterprise Linux Hpc Node6.0AllAllAll
Operating
System
RedhatEnterprise Linux Hpc Node7.0AllAllAll
Operating
System
RedhatEnterprise Linux Hpc Node6.0AllAllAll
Operating
System
RedhatEnterprise Linux Hpc Node7.0AllAllAll
Operating
System
RedhatEnterprise Linux Hpc Node Eus7.2AllAllAll
Operating
System
RedhatEnterprise Linux Hpc Node Eus7.2AllAllAll
Operating
System
RedhatEnterprise Linux Server5.0AllAllAll
Operating
System
RedhatEnterprise Linux Server6.0AllAllAll
Operating
System
RedhatEnterprise Linux Server7.0AllAllAll
Operating
System
RedhatEnterprise Linux Server5.0AllAllAll
Operating
System
RedhatEnterprise Linux Server6.0AllAllAll
Operating
System
RedhatEnterprise Linux Server7.0AllAllAll
Operating
System
RedhatEnterprise Linux Server Aus7.2AllAllAll
Operating
System
RedhatEnterprise Linux Server Aus7.2AllAllAll
Operating
System
RedhatEnterprise Linux Server Eus6.7.zAllAllAll
Operating
System
RedhatEnterprise Linux Server Eus7.2AllAllAll
Operating
System
RedhatEnterprise Linux Server Eus6.7.zAllAllAll
Operating
System
RedhatEnterprise Linux Server Eus7.2AllAllAll
Operating
System
RedhatEnterprise Linux Workstation6.0AllAllAll
Operating
System
RedhatEnterprise Linux Workstation7.0AllAllAll
Operating
System
RedhatEnterprise Linux Workstation6.0AllAllAll
Operating
System
RedhatEnterprise Linux Workstation7.0AllAllAll
ApplicationRedhatIcedtea7Allrc1AllAll
  • cpe:2.3:a:oracle:jdk:1.6.0:update_113:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:jdk:1.7.0:update_99:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:jdk:1.8.0:update77:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:jdk:1.6.0:update_113:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:jdk:1.7.0:update_99:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:jdk:1.8.0:update77:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:jre:1.6.0:update_113:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:jre:1.7.0:update_99:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:jre:1.8.0:update_77:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:jre:1.6.0:update_113:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:jre:1.7.0:update_99:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:jre:1.8.0:update_77:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:jrockit:r28.3.9:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:jrockit:r28.3.9:*:*:*:*:*:*:*:
  • cpe:2.3:o:oracle:linux:5.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:oracle:linux:6:*:*:*:*:*:*:*:
  • cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*:
  • cpe:2.3:o:oracle:linux:5.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:oracle:linux:6:*:*:*:*:*:*:*:
  • cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_hpc_node:6.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_hpc_node:6.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_hpc_node_eus:7.2:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_hpc_node_eus:7.2:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_server_eus:6.7.z:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_server_eus:7.2:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_server_eus:6.7.z:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_server_eus:7.2:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:redhat:icedtea7:*:rc1:*:*:*:*:*:*: