Vulnerability Name: | CVE-2016-0603 (CCN-110446) | ||||||||||||
Assigned: | 2015-12-09 | ||||||||||||
Published: | 2016-02-05 | ||||||||||||
Updated: | 2022-05-13 | ||||||||||||
Summary: | Unspecified vulnerability in the Java SE component in Oracle Java SE 6u111, 7u95, 8u71, and 8u72, when running on Windows, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install. Note: the previous information is from Oracle's Security Alert for CVE-2016-0603. Oracle has not commented on third-party claims that this is an untrusted search path issue that allows local users to gain privileges via a Trojan horse dll in the "application directory." | ||||||||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||
CVSS v2 Severity: | 7.6 High (CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C) 5.6 Medium (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-0603 Source: FULLDISC Type: UNKNOWN 20160210 [CVE-2016-0602, CVE-2016-0603] Executable installers are vulnerable^WEVIL (case 24): Oracle Java 6/7/8 SE and VirtualBox Source: CCN Type: IBM Security Bulletin S1010086 (N series OnCommand) Java Platform Standard Edition Vulnerability in Multiple N Series Products (CVE-2016-0603) Source: CCN Type: IBM Security Bulletin 1977112 (Content Classification) Multiple Vulnerabilities in IBM Java Runtime affect IBM Content Classification (CVE-2016-0494, CVE-2016-0466 and CVE-2016-0603) Source: CCN Type: IBM Security Bulletin 1978024 Vulnerability in IBM Java SDK affect IBM Tivoli Access Manager for e-business and IBM Security Access Manager for Web 7.0 software (CVE-2016-0603) Source: CCN Type: IBM Security Bulletin 1978159 (ILOG CPLEX Optimization Studio) Vulnerability in IBM Java Runtime affects IBM ILOG CPLEX Optimization Studio (CVE-2016-0603) Source: CCN Type: IBM Security Bulletin 1978271 (Rational Host On-Demand) Vulnerability in IBM Java Runtime affect Rational Host On-Demand (CVE-2016-0603) Source: CCN Type: IBM Security Bulletin 1978310 (Tivoli Monitoring V6) Multiple vulnerabilities in IBM Java Runtime affect IBM Tivoli Monitoring clients (CVE-2016-0603, CVE-2015-7575 plus additional CVEs.) Source: CCN Type: IBM Security Bulletin 1978311 (Decision Optimization Center) Vulnerability in IBM Java SDK affects IBM Decision Optimization Center (CVE-2016-0603) Source: CCN Type: Oracle Security Alert for CVE-2016-0603 Oracle Security Alert for CVE-2016-0603 Source: CONFIRM Type: Vendor Advisory http://www.oracle.com/technetwork/topics/security/alert-cve-2016-0603-2874360.html Source: BUGTRAQ Type: UNKNOWN 20160205 [CVE-2016-0602, CVE-2016-0603] Executable installers are vulnerable^WEVIL (case 24): Oracle Java 6/7/8 SE and VirtualBox Source: BID Type: UNKNOWN 83008 Source: SECTRACK Type: UNKNOWN 1034969 Source: XF Type: UNKNOWN oracle-java-cve20160603-code-exec(110446) Source: GENTOO Type: UNKNOWN GLSA-201610-08 Source: CONFIRM Type: UNKNOWN https://security.netapp.com/advisory/ntap-20160217-0001/ Source: CCN Type: IBM Security Bulletin 5099294 (Fabric Manager) Vulnerability in IBM Java SDK affects IBM Fabric Manager (CVE-2016-0603) Source: CCN Type: IBM Security Bulletin 1977549 Current releases of the IBM SDK, Java Technology Edition are affected by CVE-2016-0603 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: ![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |