CVE-2016-8328
low-risk
Published 2017-01-27
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java Mission Control). The supported version that is affected is Java SE: 8u112. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data. Note: Applies to Java Mission Control Installation. CVSS v3.0 Base Score 3.7 (Integrity impacts).
Do I need to act?
-
0.56% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
3
CVSS 3.7/10
Low
NETWORK
/ HIGH complexity
Affected Vendors
References (12)
Third Party Advisory
http://www.securityfocus.com/bid/95581
Third Party Advisory
http://www.securityfocus.com/bid/95581
22
/ 100
low-risk
Severity
13/34 · Low
Exploitability
2/34 · Minimal
Exposure
7/34 · Low