CVE-2016-3485

low
Published 2016-07-21 · Modified 2026-05-06
CVSS v3
2.9
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS v2
2.1
VIR risk
2.9

Description

Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; Java SE Embedded 8u91; and JRockit R28.3.10 allows local users to affect integrity via vectors related to Networking.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-3485

vendor Authored 2026-05-27

Vendor advisory: secalert_us@oracle.com — http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2016-3485.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debiansidfixed0

Application impact

VendorProductVersionsFixed
oraclejdk1.6.0
oraclejdk1.7.0
oraclejdk1.8.0
oraclejre1.6.0
oraclejre1.7.0
oraclejre1.8.0
oraclejrockitr28.3.10

References

Verify integrity in audit chain (admin only). AS-IS.