Vulnerability in Oracle Java SE, Java SE Embedded, and JRockit Components
CVE-2016-5547
5.3MEDIUM
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 27 January 2017
What is CVE-2016-5547?
An easily exploitable vulnerability exists in the Libraries component of Oracle's Java SE, Java SE Embedded, and JRockit, allowing unauthenticated attackers with network access to affect both client and server deployments. The flaw can lead to a partial denial of service (DoS) in Java applications. It is exploitable through sandboxed Java Web Start applications, applets, and directly via APIs, which enables data submission without the constraints of the sandboxed environment. This threat underscores the importance of maintaining updated software and enhancing security measures.
Affected Version(s)
Java SE 7u121
Java SE 8u112
Java SE Embedded 8u111