EXPOSURES › CVE-2016-3427
CVE-2016-3427
HIGH ⌖ ON CISA KEV · EXPLOITEDOracle Java SE and JRockit unspecified vulnerability allows remote code execution.
Oracle Java SE and JRockit contain an unspecified vulnerability that allows remote attackers to execute arbitrary code, impacting confidentiality, integrity, and availability. This vulnerability can be exploited through sandboxed Java Web Start applications and applets, or by supplying data to APIs. Given the history of critical remote code execution vulnerabilities in sandbox and applet components, this failure has a high embarrassment score due to the systemic issues in runtime security controls.
Shame score — Systemic issues in runtime security controls leading to critical remote code execution vulnerabilities.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Management Extensions (JMX). This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service.
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |