OpenJDK: incorrect handling of surrogate pairs in XML attribute values (JAXP, 8143167)
Published Apr 21, 2016
4.3
MEDIUMCVSS 3.0
EPSS 3.80%
Description
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect availability via vectors related to JAXP.
Affected products
No data.
No data.
Oracle Java for Red Hat Enterprise Linux 5
java-1.6.0-sun-1:1.6.0.115-1jpp.1.el5_11
Fixed · RHSA-2016:0679
Oracle Java for Red Hat Enterprise Linux 5
java-1.7.0-oracle-1:1.7.0.101-1jpp.1.el5_11
Fixed · RHSA-2016:0678
Oracle Java for Red Hat Enterprise Linux 6
java-1.6.0-sun-1:1.6.0.115-1jpp.1.el6_7
Fixed · RHSA-2016:0679
Oracle Java for Red Hat Enterprise Linux 6
java-1.7.0-oracle-1:1.7.0.101-1jpp.1.el6_7
Fixed · RHSA-2016:0678
Oracle Java for Red Hat Enterprise Linux 6
java-1.8.0-oracle-1:1.8.0.91-1jpp.1.el6_7
Fixed · RHSA-2016:0677
Oracle Java for Red Hat Enterprise Linux 7
java-1.6.0-sun-1:1.6.0.115-1jpp.1.el7
Fixed · RHSA-2016:0679
Oracle Java for Red Hat Enterprise Linux 7
java-1.7.0-oracle-1:1.7.0.101-1jpp.1.el7
Fixed · RHSA-2016:0678
Oracle Java for Red Hat Enterprise Linux 7
java-1.8.0-oracle-1:1.8.0.91-1jpp.1.el7
Fixed · RHSA-2016:0677
Red Hat Enterprise Linux 5
java-1.6.0-openjdk-1:1.6.0.39-1.13.11.0.el5_11
Fixed · RHSA-2016:0723
Red Hat Enterprise Linux 5
java-1.7.0-openjdk-1:1.7.0.101-2.6.6.1.el5_11
Fixed · RHSA-2016:0676
Red Hat Enterprise Linux 6
java-1.6.0-openjdk-1:1.6.0.39-1.13.11.0.el6_7
Fixed · RHSA-2016:0723
Red Hat Enterprise Linux 6
java-1.7.0-openjdk-1:1.7.0.101-2.6.6.1.el6_7
Fixed · RHSA-2016:0675
Red Hat Enterprise Linux 6
java-1.8.0-openjdk-1:1.8.0.91-0.b14.el6_7
Fixed · RHSA-2016:0651
Red Hat Enterprise Linux 7
java-1.6.0-openjdk-1:1.6.0.39-1.13.11.0.el7_2
Fixed · RHSA-2016:0723
Red Hat Enterprise Linux 7
java-1.7.0-openjdk-1:1.7.0.101-2.6.6.1.el7_2
Fixed · RHSA-2016:0676
Red Hat Enterprise Linux 7
java-1.8.0-openjdk-1:1.8.0.91-0.b14.el7_2
Fixed · RHSA-2016:0650
| Product | Package | State | Advisory |
|---|---|---|---|
| Oracle Java for Red Hat Enterprise Linux 5 | java-1.6.0-sun-1:1.6.0.115-1jpp.1.el5_11 | Fixed | RHSA-2016:0679 |
| Oracle Java for Red Hat Enterprise Linux 5 | java-1.7.0-oracle-1:1.7.0.101-1jpp.1.el5_11 | Fixed | RHSA-2016:0678 |
| Oracle Java for Red Hat Enterprise Linux 6 | java-1.6.0-sun-1:1.6.0.115-1jpp.1.el6_7 | Fixed | RHSA-2016:0679 |
| Oracle Java for Red Hat Enterprise Linux 6 | java-1.7.0-oracle-1:1.7.0.101-1jpp.1.el6_7 | Fixed | RHSA-2016:0678 |
| Oracle Java for Red Hat Enterprise Linux 6 | java-1.8.0-oracle-1:1.8.0.91-1jpp.1.el6_7 | Fixed | RHSA-2016:0677 |
| Oracle Java for Red Hat Enterprise Linux 7 | java-1.6.0-sun-1:1.6.0.115-1jpp.1.el7 | Fixed | RHSA-2016:0679 |
| Oracle Java for Red Hat Enterprise Linux 7 | java-1.7.0-oracle-1:1.7.0.101-1jpp.1.el7 | Fixed | RHSA-2016:0678 |
| Oracle Java for Red Hat Enterprise Linux 7 | java-1.8.0-oracle-1:1.8.0.91-1jpp.1.el7 | Fixed | RHSA-2016:0677 |
| Red Hat Enterprise Linux 5 | java-1.6.0-openjdk-1:1.6.0.39-1.13.11.0.el5_11 | Fixed | RHSA-2016:0723 |
| Red Hat Enterprise Linux 5 | java-1.7.0-openjdk-1:1.7.0.101-2.6.6.1.el5_11 | Fixed | RHSA-2016:0676 |
| Red Hat Enterprise Linux 6 | java-1.6.0-openjdk-1:1.6.0.39-1.13.11.0.el6_7 | Fixed | RHSA-2016:0723 |
| Red Hat Enterprise Linux 6 | java-1.7.0-openjdk-1:1.7.0.101-2.6.6.1.el6_7 | Fixed | RHSA-2016:0675 |
| Red Hat Enterprise Linux 6 | java-1.8.0-openjdk-1:1.8.0.91-0.b14.el6_7 | Fixed | RHSA-2016:0651 |
| Red Hat Enterprise Linux 7 | java-1.6.0-openjdk-1:1.6.0.39-1.13.11.0.el7_2 | Fixed | RHSA-2016:0723 |
| Red Hat Enterprise Linux 7 | java-1.7.0-openjdk-1:1.7.0.101-2.6.6.1.el7_2 | Fixed | RHSA-2016:0676 |
| Red Hat Enterprise Linux 7 | java-1.8.0-openjdk-1:1.8.0.91-0.b14.el7_2 | Fixed | RHSA-2016:0650 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Oct 15, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (25 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.80% (0.03800) | 89.67th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.80% (0.03800) | 88.58th | v5 (v2026.06.15) |
| May 13, 2026 | 7.61% (0.07607) | 91.92th | v4 (v2025.03.14) |
| Dec 28, 2025 | 9.10% (0.09098) | 92.38th | v4 (v2025.03.14) |
| Dec 27, 2025 | 6.50% (0.06497) | 90.82th | v4 (v2025.03.14) |
| Dec 24, 2025 | 9.10% (0.09098) | 92.38th | v4 (v2025.03.14) |
| Dec 23, 2025 | 7.61% (0.07607) | 91.53th | v4 (v2025.03.14) |
| Oct 31, 2025 | 9.10% (0.09098) | 92.29th | v4 (v2025.03.14) |
| Oct 30, 2025 | 7.61% (0.07607) | 91.41th | v4 (v2025.03.14) |
| Oct 28, 2025 | 9.10% (0.09098) | 92.29th | v4 (v2025.03.14) |
| Oct 27, 2025 | 6.50% (0.06497) | 90.70th | v4 (v2025.03.14) |
| Oct 1, 2025 | 9.10% (0.09098) | 92.39th | v4 (v2025.03.14) |
| May 14, 2025 | 7.29% (0.07294) | 91.16th | v4 (v2025.03.14) |
| Mar 30, 2025 | 5.12% (0.05124) | 88.86th | v4 (v2025.03.14) |
| Mar 29, 2025 | 9.27% (0.09270) | 87.77th | v4 (v2025.03.14) |
| Mar 17, 2025 | 5.12% (0.05124) | 89.10th | v4 (v2025.03.14) |
| Dec 12, 2024 | 2.20% (0.02204) | 89.84th | v3 (v2023.03.01) |
| Jun 19, 2024 | 2.20% (0.02204) | 89.49th | v3 (v2023.03.01) |
| Feb 12, 2024 | 1.57% (0.01566) | 86.82th | v3 (v2023.03.01) |
| Dec 8, 2023 | 0.77% (0.00772) | 79.21th | v3 (v2023.03.01) |
| Oct 2, 2023 | 0.69% (0.00693) | 77.84th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.68% (0.00682) | 76.90th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.53% (0.02528) | 81.92th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.53% (0.02528) | 80.15th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.53% (0.02528) | 58.66th | v2 (v2022.01.01) |
No CWE recorded.
References (30)
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00006.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00009.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00012.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00021.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00022.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00026.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00027.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2016-0650.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-0651.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-0675.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-0676.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-0677.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-0678.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-0679.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-0723.html vendor-advisoryx_refsource_REDHAT
- http://www.debian.org/security/2016/dsa-3558 vendor-advisoryx_refsource_DEBIAN
- http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html x_refsource_CONFIRMVendor Advisory
- http://www.oracle.com/technetwork/topics/security/cpuapr2016-2881694.html#AppendixJAVA
- http://www.securityfocus.com/bid/86434 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1035596 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/USN-2963-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2964-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2972-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2016-3425 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1328040 Issue Tracking
- https://kc.mcafee.com/corporate/index?page=content&id=SB10159 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2016-3425
- https://security.gentoo.org/glsa/201606-18 vendor-advisoryx_refsource_GENTOO
- https://security.netapp.com/advisory/ntap-20160420-0001/ x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2016-3425
Change history (0)
No recorded changes yet.