PT-2016-1811 · Oracle+5 · Java Se Embedded+7

Publicado

2016-04-20

·

Atualizado

2024-06-15

·

CVE-2016-0686

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Java SE versions 6u113, 7u99, and 8u77 Java SE Embedded version 8u77
Description The issue affects the confidentiality, integrity, and availability of systems through vectors related to Serialization. It is associated with errors in the code and can be exploited by remote attackers to impact the security of the system. The vulnerability allows for the escalation of privileges by modifying or removing the security manager, potentially enabling the execution of arbitrary code.
Recommendations For Java SE versions 6u113, 7u99, and 8u77, update to a version that includes the fix for this issue. For Java SE Embedded version 8u77, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting the use of Serialization to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-01144
CESA-2016_0650
CESA-2016_0651
CESA-2016_0675
CESA-2016_0676
CESA-2016_0723
CVE-2016-0686
DLA-451-1
DSA-3558-1
MGASA-2016-0149
OPENSUSE-SU-2016_1222-1
OPENSUSE-SU-2016_1230-1
OPENSUSE-SU-2016_1235-1
OPENSUSE-SU-2016_1262-1
OPENSUSE-SU-2016_1265-1
OPENSUSE-SU-2024:10197-1
OPENSUSE-SU-2024:10534-1
RHSA-2016:0650
RHSA-2016:0651
RHSA-2016:0675
RHSA-2016:0676
RHSA-2016:0677
RHSA-2016:0678
RHSA-2016:0679
RHSA-2016:0701
RHSA-2016:0702
RHSA-2016:0708
RHSA-2016:0716
RHSA-2016:0723
RHSA-2016:1039
RHSA-2016:1430
RHSA-2016_0650
RHSA-2016_0651
RHSA-2016_0675
RHSA-2016_0676
RHSA-2016_0677
RHSA-2016_0678
RHSA-2016_0679
RHSA-2016_0701
RHSA-2016_0708
RHSA-2016_0716
RHSA-2016_0723
RHSA-2016_1039
RHSA-2017:1216
SUSE-SU-2016:1248-1
SUSE-SU-2016:1250-1
SUSE-SU-2016:1299-1
SUSE-SU-2016:1300-1
SUSE-SU-2016:1303-1
SUSE-SU-2016:1378-1
SUSE-SU-2016:1379-1
SUSE-SU-2016:1458-1
SUSE-SU-2016:1475-1
SUSE-SU-2016_1248-1
SUSE-SU-2016_1250-1
USN-2963-1
USN-2964-1
USN-2972-1

Produtos afetados

Centos
Ibm Aix
Java Platform
Java Se
Java Se Embedded
Red Hat
Suse
Ubuntu