CVE-2016-3427
KEVmassImproper Access Control in Oracle Java SE and JRockit JMX Exploited in the Wild
CISA: Oracle Java SE and JRockit Unspecified Vulnerability
CVE-2016-3427 is an improper access-control flaw (CWE-284) in the JMX (Java Management Extensions) component of Oracle Java SE 6u113, 7u99, and 8u77, Java SE Embedded 8u77, and JRockit R28.3.9. Because the flaw is network-exploitable without privileges or user interaction (CVSS 3.1: 9.8), a remote, unauthenticated attacker can trigger it by sending crafted traffic to JMX-related interfaces on systems running the affected runtimes. Successful exploitation affects confidentiality, integrity, and availability, i.e., effectively a full compromise of the affected Java process, enabling data theft, tampering, and denial of service. Anyone running the affected Java or JRockit versions is exposed, including Linux distributions that package the JDK/JRE and NetApp E-Series SANtricity and OnCommand products that bundle affected Java. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2023-05-12, confirming active exploitation, and its EPSS score (~92%, 100th percentile) indicates a very high probability of exploitation; no public proof-of-concept is known.
What to do: Upgrade Java SE/JDK/JRE to releases newer than 8u77, 7u99, and 6u113 (apply Oracle's April 2016 Critical Patch Update fixes or later, or current supported Java releases), move JRockit beyond R28.3.9, and update Java SE Embedded beyond 8u77; for NetApp E-Series and OnCommand products, apply the vendor's updated releases containing fixed Java. As an interim mitigation, restrict remote JMX access to trusted management networks and monitor for anomalous JMX/RMI connections. Patching is required under CISA KEV (apply updates per vendor instructions).
| Oracle Java SE (JDK/JRE) | 6u113, 7u99, and 8u77 (and prior updates) |
| Oracle Java SE Embedded | 8u77 (and prior) |
| Oracle JRockit | R28.3.9 (and prior) |
| Canonical Ubuntu Linux (JDK/JRE packages) | — |
| Debian Linux (JDK/JRE packages) | — |
| Red Hat Linux (JDK/JRE packages) | — |
| SUSE Linux (JDK/JRE packages) | — |
| openSUSE Linux (JDK/JRE packages) | — |
| NetApp E-Series SANtricity Storage Manager | — |
| NetApp E-Series SANtricity Management Plug-ins | — |
| NetApp E-Series SANtricity Web Services | — |
| NetApp OnCommand Balance | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
- Affected
- Oracle Java SE and JRockit
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- oraclecanonicaldebiannetappapacheredhatsuseopensuse
- Products
- jdk, jre, jrockit, linux, ubuntu linux, debian linux, e-series santricity management plug-ins, e-series santricity storage manager, e-series santricity web services, oncommand balance, oncommand cloud manager, oncommand insight
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H