HIGH SEVERITY

CVE-2016-3506

Jdbc vulnerability

CVSS
8.1
EPSS
3.5%
EPSS pct
88th
Exploited
No known
Unspecified vulnerability in the JDBC component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2; the Oracle Retail Xstore Point of Service 5.5, 6.0, 6.5, 7.0, 7.1, 15.0, and 16.0; the Oracle Retail Warehouse Management System 14.04, 14.1.3, and 15.0.1; the Oracle Retail Workforce Management 1.60.7, and 1.64.0; the Oracle Retail Clearance Optimization Engine 13.4; the Oracle Retail Markdown Optimization 13.4 and 14.0; and Oracle Retail Merchandising System 16.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
Affected vendor
Oracle
Affected product
Jdbc
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Published
2016-07-21

Risk analysis

Based on its CVSS vector, this vulnerability is exploitable over the network, high attack complexity, requiring no privileges, no user interaction. Successful exploitation leads to high impact to confidentiality, high impact to integrity, high impact to availability.

Its EPSS score of 3.5% reflects a lower probability of exploitation activity in the wild over the next 30 days, placing it above 88% of all scored CVEs.

Check your external exposure to CVE-2016-3506

  • Confirm whether Oracle Jdbc is running on any internet-facing host or subdomain.
  • Match discovered service fingerprints against the version affected by CVE-2016-3506.
  • Prioritise remediation if the asset is public, business-critical, or near authentication/payment flows.

How ThreatPort helps with CVE-2016-3506

ThreatPort's external attack surface scanner checks your internet-facing assets — agentlessly, from the outside in — for the exposed services and versions that CVE-2016-3506 affects, then prioritises the finding by real risk using CISA KEV and FIRST.org EPSS.

Run a free external exposure scan

Are you exposed to CVE-2016-3506?

Run an instant, non-intrusive external scan to check your attack surface for CVE-2016-3506.

Start free scan

No credit card. Agentless.