Vulnerability in Oracle Java SE 8 and Embedded Java SE Products
CVE-2016-3587

9.6CRITICAL

Key Information:

Vendor
Oracle
Status
Vendor
CVE Published:
21 July 2016

Summary

A vulnerability exists in both Oracle Java SE 8u92 and Java SE Embedded 8u91 that may allow remote attackers to potentially compromise the confidentiality, integrity, and availability of software systems. The issue relates to the Hotspot component, which is responsible for executing Java applications. Due to insufficient validation within this area, an attacker could exploit the vulnerability through crafted inputs, jeopardizing system functionality and data integrity.

References

EPSS Score

8% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.