CVE ID | CVE-2016-3606 |
CVSS SCORE | 6.8, AV:N/AC:M/Au:N/C:P/I:P/A:P |
AFFECTED VENDORS |
Oracle |
AFFECTED PRODUCTS |
Java |
VULNERABILITY DETAILS |
The specific flaw exists within the way the runtime evaluates uninitialized objects that are not compiler generated. Due to unsafe handling of privileged classes within the uninitialized objects, it is possible for untrusted code to gain access to privileged methods and properties. This can result in remote code execution under the context of the current process. |
ADDITIONAL DETAILS | |
DISCLOSURE TIMELINE |
|
CREDIT | XOR19 |