cbcvebase.
CVE-2016-1000027
published 2020-01-02

CVE-2016-1000027: Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data…

PriorityP265critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
32.26%
98.1th percentile
Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.

Affected

3 ranges
VendorProductVersion rangeFixed in
debianlibspring-java< libspring-java 4.2.7-1 (bookworm)libspring-java 4.2.7-1 (bookworm)
thorntechsftp_gateway_firmware>= 3.4.0 < 3.4.43.4.4
vmwarespring_framework< 6.0.06.0.0

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerable component is `HttpInvokerServiceExporter` and its `readRemoteInvocation` method in Spring Framework — monitor for HTTP requests targeting endpoints exposed via `org.springframework.remoting.httpinvoker.*`
  • Look for Java deserialization payloads delivered over HTTP to Spring HttpInvoker endpoints; the attack vector is remote and unauthenticated in some configurations
  • Flag any direct usage of classes under `org.springframework.remoting.httpinvoker.*` in deployed applications, as this is the attack surface for CVE-2016-1000027
  • Reference Tenable research TRA-2016-20 for additional technical exploitation details and detection guidance for this deserialization vulnerability
  • ·Exploitation depends entirely on whether the application exposes HttpInvoker endpoints to untrusted clients — internal/authenticated-only deployments significantly reduce risk
  • ·The Spring vendor will NOT patch this behavior; the fix is architectural — HttpInvoker endpoints must not be exposed to untrusted clients. Upstream 'fix' was documentation-only (commit 5cbe90b2cd91b866a5a9586e460f311860e11cfa)
  • ·The upstream documentation fix was included in Spring 3.2.17; Fuse 6.3 R5 (RHSA-2017:3115) shipped Spring 3.2.18 which contains this documentation change

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.