CVE-2016-3690
published 2017-06-08CVE-2016-3690: The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.
PriorityP354critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
5.24%
91.6th percentile
The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8phf-82cj-4m65: The PooledInvokerServlet in JBoss EAP 4
ghsa_unreviewed·2022-05-17
CVE-2016-3690 [CRITICAL] CWE-502 GHSA-8phf-82cj-4m65: The PooledInvokerServlet in JBoss EAP 4
The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.
Red Hat
PooledInvokerServlet is not secured, and deserializes data
vendor_redhat·2016-06-13·CVSS 9.8
CVE-2016-3690 [CRITICAL] CWE-502 PooledInvokerServlet is not secured, and deserializes data
PooledInvokerServlet is not secured, and deserializes data
The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.
It was discovered that the LegacyInvokerServlet is exposed on all network interfaces and deserializes objects sent to it. An attacker could use this flaw to cause remote code execution in the JVM running it.
Mitigation: The PooledInvokerServlet is no longer required and can be removed by following the details in this knowledgebase solution: https://access.redhat.com/solutions/178393
Package: jbossas (Red Hat JBoss BRMS 5) - Will not fix
Package: jbossas (Red Hat JBoss Enterprise Application Platform 4) - Will not fix
Package: jbossas (Red Hat JBoss Enterprise Application Platform 5) - Will not
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/99079https://access.redhat.com/solutions/178393https://access.redhat.com/solutions/45530https://bugzilla.redhat.com/show_bug.cgi?id=1327037http://www.securityfocus.com/bid/99079https://access.redhat.com/solutions/178393https://access.redhat.com/solutions/45530https://bugzilla.redhat.com/show_bug.cgi?id=1327037
2017-06-08
Published