Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-0360

Опубликовано: 15 фев. 2017
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

IBM Websphere MQ JMS 7.0.1, 7.1, 7.5, 8.0, and 9.0 client provides classes that deserialize objects from untrusted sources which could allow a malicious user to execute arbitrary Java code by adding vulnerable classes to the classpath. IBM Reference #: 1983457.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ibm:websphere_mq_jms:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_mq_jms:7.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_mq_jms:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_mq_jms:8.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_mq_jms:9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 76%
0.00962
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

IBM Websphere MQ JMS 7.0.1, 7.1, 7.5, 8.0, and 9.0 client provides classes that deserialize objects from untrusted sources which could allow a malicious user to execute arbitrary Java code by adding vulnerable classes to the classpath. IBM Reference #: 1983457.

EPSS

Процентиль: 76%
0.00962
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-502