CVE-2016-0264: IBM Java SDK

Medium severity, CVSS 5.6. EPSS: 3.9% chance of exploitation in the next 30 days.

Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) allows remote attackers to execute arbitrary code via unspecified vectors.

Affected products

  • IBM Java SDK: from 6.0.0.0, before 6.0.16.25 (fixed in 6.0.16.25); from 6.1.0.0, before 6.1.8.25 (fixed in 6.1.8.25); from 7.0.0.0, before 7.0.9.40 (fixed in 7.0.9.40); from 7.1.0.0, before 7.1.3.40 (fixed in 7.1.3.40); from 8.0.0.0, before 8.0.3.0 (fixed in 8.0.3.0)
  • Red Hat Enterprise Linux Desktop: version 5.0 only; version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Hpc Node Supplementary: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server: version 5.0 only; version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server Eus: version 6.7 only; version 7.2 only; version 7.3 only; version 7.4 only; version 7.5 only
  • Red Hat Enterprise Linux Workstation: version 5.0 only; version 6.0 only; version 7.0 only
  • Red Hat Satellite: version 5.6 only; version 5.7 only
  • Suse Linux Enterprise Server: version 11 only; version 10 only; version 12 only
  • Suse Linux Enterprise Software Development Kit: version 11 only; version 12 only
  • Suse Manager: version 2.1 only
  • Suse Manager Proxy: version 2.1 only
  • Suse Openstack Cloud: version 5 only
  • Suse Suse Linux Enterprise Server: version 12 only

Published 2016-05-24. Last modified 2026-06-17.