Логотип exploitDog
bind:CVE-2016-1000027
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2016-1000027

Количество 6

Количество 6

ubuntu логотип

CVE-2016-1000027

больше 5 лет назад

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.

CVSS3: 9.8
EPSS: Средний
redhat логотип

CVE-2016-1000027

около 9 лет назад

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2016-1000027

больше 5 лет назад

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2016-1000027

больше 5 лет назад

Pivotal Spring Framework through 5.3.16 suffers from a potential remot ...

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-4wrc-f8pq-fpqp

около 3 лет назад

Pivotal Spring Framework contains unsafe Java deserialization methods

CVSS3: 9.8
EPSS: Средний
fstec логотип

BDU:2022-02190

больше 9 лет назад

Уязвимость реализации метода readRemoteInvocation обработчика HTTP-запросов на основе Servlet-API HttpInvokerServiceExporter программной платформы Spring Framework, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2016-1000027

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.

CVSS3: 9.8
49%
Средний
больше 5 лет назад
redhat логотип
CVE-2016-1000027

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.

CVSS3: 9.8
49%
Средний
около 9 лет назад
nvd логотип
CVE-2016-1000027

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.

CVSS3: 9.8
49%
Средний
больше 5 лет назад
debian логотип
CVE-2016-1000027

Pivotal Spring Framework through 5.3.16 suffers from a potential remot ...

CVSS3: 9.8
49%
Средний
больше 5 лет назад
github логотип
GHSA-4wrc-f8pq-fpqp

Pivotal Spring Framework contains unsafe Java deserialization methods

CVSS3: 9.8
49%
Средний
около 3 лет назад
fstec логотип
BDU:2022-02190

Уязвимость реализации метода readRemoteInvocation обработчика HTTP-запросов на основе Servlet-API HttpInvokerServiceExporter программной платформы Spring Framework, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
49%
Средний
больше 9 лет назад

Уязвимостей на страницу