Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-13759

Опубликовано: 30 июн. 2026
Источник: nvd
CVSS3: 7.5
CVSS3: 8.8
EPSS Низкий

Описание

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, ObjectStreamPool$ReusableInputStream, ObjectInputStreamResolver) that install no JEP-290 class filter; when Coherence is on the classpath, multiple RCE gadget chains including RemoteConstructor.readResolve and PriorityQueue/ExtractorComparator are confirmed working, allowing a post-login attacker who can write a session attribute or a LAN-adjacent attacker on the grid replication wire to execute arbitrary code on peer WAS JVMs

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ibm:websphere_extreme_scale:*:*:*:*:*:*:*:*
Версия от 8.6.1.0 (включая) до 8.6.1.6 (включая)

EPSS

Процентиль: 22%
0.00303
Низкий

7.5 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 7.5
github
около 1 месяца назад

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, ObjectStreamPool$ReusableInputStream, ObjectInputStreamResolver) that install no JEP-290 class filter; when Coherence is on the classpath, multiple RCE gadget chains including RemoteConstructor.readResolve and PriorityQueue/ExtractorComparator are confirmed working, allowing a post-login attacker who can write a session attribute or a LAN-adjacent attacker on the grid replication wire to execute arbitrary code on peer WAS JVMs

EPSS

Процентиль: 22%
0.00303
Низкий

7.5 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-502