Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-7050

Опубликовано: 23 сент. 2016
Источник: redhat
CVSS3: 9
CVSS2: 6.8

Описание

SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to execute arbitrary code.

It was discovered that under certain conditions RESTEasy could be forced to parse a request with SerializableProvider, resulting in deserialization of potentially untrusted data. An attacker could possibly use this flaw execute arbitrary code with the permissions of the application using RESTEasy.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 6resteasyNot affected
Red Hat JBoss Enterprise Application Platform 7resteasy-coreNot affected
Red Hat JBoss Fuse 6resteasyNot affected
Red Hat Enterprise Linux 7resteasy-baseFixedRHSA-2016:260403.11.2016

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=1378613RESTEasy: SerializableProvider enabled by default and deserializes untrusted data

9 Critical

CVSS3

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to execute arbitrary code.

CVSS3: 9.8
nvd
больше 8 лет назад

SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to execute arbitrary code.

CVSS3: 9.8
debian
больше 8 лет назад

SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7 ...

CVSS3: 9.8
github
больше 3 лет назад

SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to execute arbitrary code.

oracle-oval
почти 9 лет назад

ELSA-2016-2604: resteasy-base security and bug fix update (IMPORTANT)

9 Critical

CVSS3

6.8 Medium

CVSS2