CVE-2016-1000027
published 2020-01-02CVE-2016-1000027: Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data…
PriorityP265critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
32.26%
98.1th percentile
Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libspring-java | < libspring-java 4.2.7-1 (bookworm) | libspring-java 4.2.7-1 (bookworm) |
| thorntech | sftp_gateway_firmware | >= 3.4.0 < 3.4.4 | 3.4.4 |
| vmware | spring_framework | < 6.0.0 | 6.0.0 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerable component is `HttpInvokerServiceExporter` and its `readRemoteInvocation` method in Spring Framework — monitor for HTTP requests targeting endpoints exposed via `org.springframework.remoting.httpinvoker.*` ↗
- →Look for Java deserialization payloads delivered over HTTP to Spring HttpInvoker endpoints; the attack vector is remote and unauthenticated in some configurations ↗
- →Flag any direct usage of classes under `org.springframework.remoting.httpinvoker.*` in deployed applications, as this is the attack surface for CVE-2016-1000027 ↗
- →Reference Tenable research TRA-2016-20 for additional technical exploitation details and detection guidance for this deserialization vulnerability ↗
- ·Exploitation depends entirely on whether the application exposes HttpInvoker endpoints to untrusted clients — internal/authenticated-only deployments significantly reduce risk ↗
- ·The Spring vendor will NOT patch this behavior; the fix is architectural — HttpInvoker endpoints must not be exposed to untrusted clients. Upstream 'fix' was documentation-only (commit 5cbe90b2cd91b866a5a9586e460f311860e11cfa) ↗
- ·The upstream documentation fix was included in Spring 3.2.17; Fuse 6.3 R5 (RHSA-2017:3115) shipped Spring 3.2.18 which contains this documentation change ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Analytics Risk Matrix: Development Operations (Spring Framework) — CVE-2016-1000027
vendor_oracle·2025-01-15·CVSS 9.8
CVE-2016-1000027 [CRITICAL] Oracle Oracle Analytics Risk Matrix: Development Operations (Spring Framework) — CVE-2016-1000027
Oracle Oracle Analytics Risk Matrix: Development Operations (Spring Framework) vulnerability
CVE: CVE-2016-1000027
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
Red Hat
spring: HttpInvokerServiceExporter readRemoteInvocation method untrusted java deserialization
vendor_redhat·2016-07-08·CVSS 9.8
CVE-2016-1000027 [CRITICAL] CWE-502 spring: HttpInvokerServiceExporter readRemoteInvocation method untrusted java deserialization
spring: HttpInvokerServiceExporter readRemoteInvocation method untrusted java deserialization
Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.
Package: jenkins (OpenShift Developer Tools and Services) - Not affected
Package: jasperreports-server-pro (Red Hat Enterprise Virtualization 3) - Not affected
Package: redhat-support-plugin-rhev (Red Hat Enterprise Virtualization 3) - Not a
Debian
CVE-2016-1000027: libspring-java - Pivotal Spring Framework through 5.3.16 suffers from a potential remote code exe...
vendor_debian·2016·CVSS 9.8
CVE-2016-1000027 [CRITICAL] CVE-2016-1000027: libspring-java - Pivotal Spring Framework through 5.3.16 suffers from a potential remote code exe...
Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.
Scope: local
bookworm: resolved (fixed in 4.2.7-1)
bullseye: resolved (fixed in 4.2.7-1)
forky: resolved (fixed in 4.2.7-1)
sid: resolved (fixed in 4.2.7-1)
trixie: resolved (fixed in 4.2.7-1)
GHSA
GHSA-jh46-rmg6-r59w: Thorn SFTP gateway 3
ghsa_unreviewed·2023-10-31·CVSS 9.8
CVE-2023-47174 [CRITICAL] CWE-502 GHSA-jh46-rmg6-r59w: Thorn SFTP gateway 3
Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal, a related issue to CVE-2016-1000027. Also, within the specific context of Thorn SFTP gateway, this leads to remote code execution.
GHSA
Pivotal Spring Framework contains unsafe Java deserialization methods
ghsa·2022-05-24
CVE-2016-1000027 [CRITICAL] CWE-502 Pivotal Spring Framework contains unsafe Java deserialization methods
Pivotal Spring Framework contains unsafe Java deserialization methods
Pivotal Spring Framework before 6.0.0 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required.
Maintainers recommend investigating alternative components or a potential mitigating control. Version 4.2.6 and 3.2.17 contain [enhanced documentation](https://github.com/spring-projects/spring-framework/commit/5cbe90b2cd91b866a5a9586e460f311860e11cfa) advising users to take precautions against unsafe Java deserialization, version 5.3.0 [deprecate the impacted classes](https://github.com/spring-projects/spring-framework/issues/25379) and version 6.
OSV
Pivotal Spring Framework contains unsafe Java deserialization methods
osv·2022-05-24
CVE-2016-1000027 [CRITICAL] Pivotal Spring Framework contains unsafe Java deserialization methods
Pivotal Spring Framework contains unsafe Java deserialization methods
Pivotal Spring Framework before 6.0.0 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required.
Maintainers recommend investigating alternative components or a potential mitigating control. Version 4.2.6 and 3.2.17 contain [enhanced documentation](https://github.com/spring-projects/spring-framework/commit/5cbe90b2cd91b866a5a9586e460f311860e11cfa) advising users to take precautions against unsafe Java deserialization, version 5.3.0 [deprecate the impacted classes](https://github.com/spring-projects/spring-framework/issues/25379) and version 6.
OSV
CVE-2016-1000027: Pivotal Spring Framework through 5
osv·2020-01-02·CVSS 9.8
CVE-2016-1000027 [CRITICAL] CVE-2016-1000027: Pivotal Spring Framework through 5
Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.
No detection rules found.
No public exploits indexed.
Qualys
Oracle Critical Patch Update, January 2025 Security Update Review
blogs_qualys·2025-01-23
Oracle Critical Patch Update, January 2025 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Oracle released its first quarterly edition of this year’s Critical Patch Update, which received patches for 318 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 85 constituting about 27% of the total patches released. Oracle MySQL and Oracle Financial Services Applications followed,
Qualys
Oracle Critical Patch Update, January 2025 Security Update Review | Qualys
blogs_qualys·2025-01-23
Oracle Critical Patch Update, January 2025 Security Update Review | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
Oracle released its first quarterly edition of this year’s Critical Patch Update, which received patches for 318 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 85 constituting about 27% of the total patches released. Oracle MySQL and Oracle Financial Services Applications fol
Bugzilla
CVE-2016-1000027 spring: HttpInvokerServiceExporter readRemoteInvocation method untrusted java deserialization
bugzilla·2016-07-19·CVSS 9.8
CVE-2016-1000027 [CRITICAL] CVE-2016-1000027 spring: HttpInvokerServiceExporter readRemoteInvocation method untrusted java deserialization
CVE-2016-1000027 spring: HttpInvokerServiceExporter readRemoteInvocation method untrusted java deserialization
Current installations of Pivotal's Spring Framework suffer from a potential remote code execution (RCE) issue. Depending on how the library is implemented within a product, it may or may not manifest, and authentication may be required.
External References:
https://www.tenable.com/security/research/tra-2016-20
Discussion:
Marking Red Hat JBoss Fuse 6 and Red Hat Fuse 7 as not affected, although versions before the documentation update (https://github.com/spring-projects/spring-framework/commit/5cbe90b2cd91b866a5a9586e460f311860e11cfa) where shipped at the time there is no use direct usage of org.springframework.remoting.httpinvoker.*
This was fixed upstream by detailing Http
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1000027https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-579669626https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-582313417https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-744519525https://raw.githubusercontent.com/distributedweaknessfiling/cvelist/master/2016/1000xxx/CVE-2016-1000027.jsonhttps://security-tracker.debian.org/tracker/CVE-2016-1000027https://security.netapp.com/advisory/ntap-20230420-0009/https://spring.io/blog/2022/05/11/spring-framework-5-3-20-and-5-2-22-available-nowhttps://www.tenable.com/security/research/tra-2016-20https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1000027https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-579669626https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-582313417https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-744519525https://raw.githubusercontent.com/distributedweaknessfiling/cvelist/master/2016/1000xxx/CVE-2016-1000027.jsonhttps://security-tracker.debian.org/tracker/CVE-2016-1000027https://security.netapp.com/advisory/ntap-20230420-0009/https://spring.io/blog/2022/05/11/spring-framework-5-3-20-and-5-2-22-available-nowhttps://www.tenable.com/security/research/tra-2016-20
2020-01-02
Published