CVE-2016-3427Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
CWE-284 · Improper access control
Exploited in the wild
Confirmed real-world exploitation.
CVSS E:A
A defect of the type ARMR addresses, with a fix path to work from and a working exploit already published. This is a claim on attention, not a scheduling commitment: no rule exists and none is scheduled.
| Decided by | patch-hint : A reference pointing at the upstream fix: a commit, a PR, a Red Hat bug |
|---|---|
| Finding | A reference points at an upstream fix (redhat-cve tier): https://access.redhat.com/security/cve/CVE-2016-3427. That makes this CVE a candidate for an ARMR patch rule — it is the kind of defect ARMR can address, and there is a fix to work from. No rule exists and none is scheduled: writing one means reading the linked change and finding a hook point ARMR can express it at, which may turn out not to exist. |
| Candidate fix | https://access.redhat.com/security/cve/CVE-2016-3427 : a Red Hat CVE page: the weakest tier, pinning no commit, but its existence means Red Hat triaged and shipped the CVE |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
3 metrics
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 3.1 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
NVD | Primary | published |
| CVSS 3.1 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CISA-ADP | Secondary | |
| CVSS 2.0 | 10.0 | no band published | AV:N/AC:L/Au:N/C:C/I:C/A:C |
NVD | Primary |
| Advisory | Type | Quarter | Products Oracle named in risk matrix |
|---|---|---|---|
| Oracle Critical Patch Update April 2016 ↗ | CPU | 2016-Q2 | Oracle Java SE / JMX (Java SE: 6u113, 7u99, 8u77; Java SE Embedded: 8u77; JRockit: R28.3.9) |
| Family | Component | Oracle's version cell (verbatim) | Indexed as |
|---|---|---|---|
| Oracle Java SE | JMX | Java SE: 6u113, 7u99, 8u77; Java SE Embedded: 8u77; JRockit: R28.3.9 | 6.0.113.0 · 7.0.99.0 · 8.0.77.0 |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| nvd | apache | cassandra | generic | ≥ 2.1.0 and < 2.1.22 · ≥ 2.2.0 and < 2.2.18 · ≥ 3.0.0 and < 3.0.22 · ≥ 3.11.0 and < 3.11.8 · 4.0.0:beta1 |
| nvd | canonical | ubuntu linux | generic | 12.04 · 14.04 · 15.10 · 16.04 |
| nvd | debian | debian linux | generic | 8.0 |
| nvd | netapp | e-series santricity management plug-ins | generic | any version |
| nvd | netapp | e-series santricity storage manager | generic | any version |
| nvd | netapp | e-series santricity web services | generic | any version |
| nvd | netapp | oncommand balance | generic | any version |
| nvd | netapp | oncommand cloud manager | generic | any version |
| nvd | netapp | oncommand insight | generic | any version |
| nvd | netapp | oncommand performance manager | generic | any version |
| nvd | netapp | oncommand report | generic | any version |
| nvd | netapp | oncommand shift | generic | any version |
| nvd | netapp | oncommand unified manager | generic | any version |
| nvd | netapp | oncommand workflow automation | generic | any version |
| nvd | netapp | storagegrid | generic | ≤ 9.0.4 |
| nvd | netapp | vasa provider for clustered data ontap | generic | ≥ 7.2 |
| nvd | netapp | virtual storage console | generic | ≥ 7.2 |
| nvd | opensuse | leap | generic | 42.1 |
| nvd | opensuse | opensuse | generic | 13.1 · 13.2 |
| nvd | oracle | jdk | javase | 1.6.0:update113 · 1.7.0:update99 · 1.8.0:update77 |
| nvd | oracle | jre | javase | 1.6.0:update113 · 1.7.0:update99 · 1.8.0:update77 |
| nvd | oracle | jrockit | generic | r28.3.9 |
| nvd | oracle | linux | generic | 5 · 6 · 7 |
| nvd | redhat | enterprise linux desktop | generic | 5.0 · 6.0 · 7.0 |
| nvd | redhat | enterprise linux eus | generic | 6.7 · 7.2 · 7.3 · 7.4 · 7.5 · 7.6 · 7.7 |
| nvd | redhat | enterprise linux server | generic | 5.0 · 6.0 · 7.0 |
| nvd | redhat | enterprise linux server aus | generic | 7.2 · 7.3 · 7.4 · 7.6 · 7.7 |
| nvd | redhat | enterprise linux server eus | generic | 6.7 · 7.2 |
| nvd | redhat | enterprise linux server tus | generic | 7.2 · 7.3 · 7.6 · 7.7 |
| nvd | redhat | enterprise linux workstation | generic | 5.0 · 6.0 · 7.0 |
| nvd | redhat | satellite | generic | 5.6 · 5.7 |
| nvd | suse | linux enterprise desktop | generic | 12 · 12:sp1 |
| nvd | suse | linux enterprise module for legacy | generic | 12 |
| nvd | suse | linux enterprise server | generic | 10:sp4 · 11:sp2 · 11:sp3 · 11:sp4 · 12 · 12:sp1 |
| nvd | suse | linux enterprise software development kit | generic | 11:sp4 · 12:sp1 |
| nvd | suse | manager | generic | 2.1 |
| nvd | suse | manager proxy | generic | 2.1 |
| nvd | suse | openstack cloud | generic | 5 |
| URL | Tags |
|---|---|
| https://access.redhat.com/security/cve/CVE-2016-3427 | redhat-cve |
| https://access.redhat.com/errata/RHSA-2016:0650 | ADVISORY, RHSA-2016:0650 |
| https://access.redhat.com/errata/RHSA-2016:0651 | ADVISORY, RHSA-2016:0651 |
| https://access.redhat.com/errata/RHSA-2016:0675 | ADVISORY, RHSA-2016:0675 |
| https://access.redhat.com/errata/RHSA-2016:0676 | ADVISORY, RHSA-2016:0676 |
| https://access.redhat.com/errata/RHSA-2016:0677 | ADVISORY, RHSA-2016:0677 |
| https://access.redhat.com/errata/RHSA-2016:0716 | ADVISORY, RHSA-2016:0716 |
| https://access.redhat.com/errata/RHSA-2016:0723 | ADVISORY, RHSA-2016:0723 |
| https://access.redhat.com/errata/RHSA-2016:1039 | ADVISORY, RHSA-2016:1039 |
| https://www.oracle.com/security-alerts/cpuapr2016v3.html |
| Published | 2016-04-21 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-06-17 | NVD's own last-modified date for this record. |