VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 19 hours ago
Reset
More filters (2)
Columns
Protection: fullAdvisory: Oracle Critical Patch Update April 2016
Overview 8 matches, all in RASP scope, all protected · 0 KEV · 2 public PoC · 0 CISA SSVC · 2 EPSS ≥ 0.5 · 0 disputed
8matches, all in RASP scope, all protected 0KEV0.0% 2public PoC25.0% 0CISA SSVC0.0% 2EPSS ≥ 0.525.0% 0disputed0.0%
Critical 5 62.5% High 0 0.0% Medium 2 25.0% Low 1 12.5% None 0 0.0% Unknown 0 0.0%
Protected by RASP 3 37.5% Rule in development 0 0.0% Mitigation candidate 0 0.0% No exploit published 0 0.0% No fix identified 0 0.0% Mitigated by environment configuration 5 62.5% Queued for review 0 0.0% Not applicable 0 0.0% Out of RASP scope 0 0.0% Rejected 0 0.0%
blocked by ARMR today 8 100.0% not blocked 0 0.0% not established 0 0.0% unrecorded 0 0.0%
split by peak 7 / quarter
Unknown: 0None: 0Low: 1Medium: 2High: 0Critical: 5 Rejected: 0Out of RASP scope: 0Not applicable: 0Queued for review: 0Mitigated by environment configuration: 5No fix identified: 0No exploit published: 0Mitigation candidate: 0Rule in development: 0Protected by RASP: 3 unrecorded: 0not established: 0not blocked: 0blocked by ARMR today: 8 No public exploit: 6Forecast only: 0Proof of concept only: 1Working exploit published: 1Exploited in the wild: 0 Q2 2016: 7 CVEs Q3 2016: 0 CVEs Q4 2016: 0 CVEs Q1 2017: 0 CVEs Q2 2017: 0 CVEs Q3 2017: 0 CVEs Q4 2017: 1 CVE
Q2 16Q3 16Q4 16Q1 17Q2 17Q3 17Q4 17
8 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2015-7501 Critical 2017-11-09 Protected by RASP Working exploit published Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
CVE-2016-3443 Critical 2016-04-21 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to 2D. NOTE: the previous information is from the April 2016 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to obtain sensitive information via crafted font data, which triggers an out-of-bounds read.
CVE-2016-3426 Low 2016-04-21 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality via vectors related to JCE.
CVE-2016-3425 Medium 2016-04-21 Protected by RASP No public exploit Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect availability via vectors related to JAXP.
CVE-2016-3422 Medium 2016-04-21 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect availability via vectors related to 2D.
CVE-2016-0687 Critical 2016-04-21 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to the Hotspot sub-component.
CVE-2016-0686 Critical 2016-04-21 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Serialization.
CVE-2016-0638 Critical 2016-04-21 Protected by RASP Proof of concept only Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Messaging Service.