CVE-2016-4000
published 2017-07-06CVE-2016-4000: Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.
PriorityP352critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
6.40%
92.9th percentile
Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | jython | < jython 2.5.3-17 (bookworm) | jython 2.5.3-17 (bookworm) |
| jython_project | jython | — | — |
| jython_project | jython | >= 0 < 2.5.3-17 | 2.5.3-17 |
| jython_project | jython | >= 0 < 2.5.3-17 | 2.5.3-17 |
| jython_project | jython | >= 0 < 2.5.3-17 | 2.5.3-17 |
| jython_project | jython | >= 0 < 2.5.3-17 | 2.5.3-17 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Deserialization of Untrusted Data in Jython
osv·2022-05-13
CVE-2016-4000 [CRITICAL] Deserialization of Untrusted Data in Jython
Deserialization of Untrusted Data in Jython
Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.
GHSA
Deserialization of Untrusted Data in Jython
ghsa·2022-05-13
CVE-2016-4000 [CRITICAL] CWE-502 Deserialization of Untrusted Data in Jython
Deserialization of Untrusted Data in Jython
Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.
OSV
CVE-2016-4000: Jython before 2
osv·2017-07-06·CVSS 9.8
CVE-2016-4000 [CRITICAL] CVE-2016-4000: Jython before 2
Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.
Oracle
Oracle Oracle Supply Chain Risk Matrix: Middle Tier (jython) — CVE-2016-4000
vendor_oracle·2020-07-15·CVSS 9.8
CVE-2016-4000 [CRITICAL] Oracle Oracle Supply Chain Risk Matrix: Middle Tier (jython) — CVE-2016-4000
Oracle Oracle Supply Chain Risk Matrix: Middle Tier (jython) vulnerability
CVE: CVE-2016-4000
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Oracle
Oracle Oracle Communications Applications Risk Matrix: IDIH Visualization (Jython) — CVE-2016-4000
vendor_oracle·2020-04-15·CVSS 9.8
CVE-2016-4000 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: IDIH Visualization (Jython) — CVE-2016-4000
Oracle Oracle Communications Applications Risk Matrix: IDIH Visualization (Jython) vulnerability
CVE: CVE-2016-4000
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Oracle Flow Builder (Jython) — CVE-2016-4000
vendor_oracle·2020-01-15·CVSS 9.8
CVE-2016-4000 [CRITICAL] Oracle Oracle Enterprise Manager Risk Matrix: Oracle Flow Builder (Jython) — CVE-2016-4000
Oracle Oracle Enterprise Manager Risk Matrix: Oracle Flow Builder (Jython) vulnerability
CVE: CVE-2016-4000
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
Cisco
Cisco Industrial Ethernet 4000 and Ethernet 5000 Series Switches ICMP IPv4 Packet Corruption Vulnerability
vendor_cisco·2016-05-13·CVSS 5.0
CVE-2016-1399 [MEDIUM] CWE-399 Cisco Industrial Ethernet 4000 and Ethernet 5000 Series Switches ICMP IPv4 Packet Corruption Vulnerability
Cisco Industrial Ethernet 4000 and Ethernet 5000 Series Switches ICMP IPv4 Packet Corruption Vulnerability
A vulnerability in the packet processing microcode of Cisco Industrial Ethernet 4000 Series Switches and Cisco Industrial Ethernet 5000 Series Switches could allow an unauthenticated, remote attacker to corrupt packets enqueued on the device for further processing.
The vulnerability is due to improper processing of some ICMP IPv4 packets. An attacker could exploit this vulnerability by sending ICMP IPv4 packets to an affected device. A successful exploit could allow an attacker to corrupt the packet enqueued immediately after the packet sent. This may impact control traffic to the device itself (Address Resolution Protocol (ARP) traffic) or traffic transiting the device.
Cisco has
Red Hat
jython: Unsafe deserialization leads to code execution
vendor_redhat·2016-02-01·CVSS 9.8
CVE-2016-4000 [CRITICAL] CWE-502 jython: Unsafe deserialization leads to code execution
jython: Unsafe deserialization leads to code execution
Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.
Package: jython (Red Hat Enterprise Linux 6) - Not affected
Package: jython (Red Hat JBoss Fuse Service Works 6) - Will not fix
Package: jython (Red Hat JBoss SOA Platform 5) - Will not fix
Package: jython (Red Hat OpenShift Enterprise 2) - Not affected
Package: rh-eclipse46-jython (Red Hat Software Collections) - Not affected
Debian
CVE-2016-4000: jython - Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted ...
vendor_debian·2016·CVSS 9.8
CVE-2016-4000 [CRITICAL] CVE-2016-4000: jython - Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted ...
Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.
Scope: local
bookworm: resolved (fixed in 2.5.3-17)
bullseye: resolved (fixed in 2.5.3-17)
forky: resolved (fixed in 2.5.3-17)
sid: resolved (fixed in 2.5.3-17)
trixie: resolved (fixed in 2.5.3-17)
Cisco
Cisco Industrial Ethernet 4000 and Ethernet 5000 Series Switches ICMP IPv4 Packet Corruption Vulnerability
vendor_cisco
CVE-2016-1399 Cisco Industrial Ethernet 4000 and Ethernet 5000 Series Switches ICMP IPv4 Packet Corruption Vulnerability
CVE-2016-1399: Cisco Industrial Ethernet 4000 and Ethernet 5000 Series Switches ICMP IPv4 Packet Corruption Vulnerability
A vulnerability in the packet processing microcode of Cisco Industrial Ethernet 4000 Series Switches and Cisco Industrial Ethernet 5000 Series Switches could allow an unauthenticated, remote attacker to corrupt packets enqueued on the device for further processing. The vulnerability is due to improper processing of some ICMP IPv4 packets. An attacker could exploit this vulnerability by sending ICMP IPv4 packets to an affected device. A successful exploit could allow an attacker to corrupt the packet enqueued immediately after the packet sent. This may impact control traffic to the device itself (Address Resolution Protocol (ARP) traffic) or traffic transiting the device
No detection rules found.
Bugzilla
CVE-2016-4000 jython: Unsafe deserialization leads to code execution
bugzilla·2017-06-15·CVSS 9.8
CVE-2016-4000 [CRITICAL] CVE-2016-4000 jython: Unsafe deserialization leads to code execution
CVE-2016-4000 jython: Unsafe deserialization leads to code execution
It was found that jython is vulnerable to arbitrary code executionby sending a serialized function to the deserializer, which in turn will execute the code.
Upstream issue:
http://bugs.jython.org/issue2454
Upstream patch:
https://hg.python.org/jython/rev/d06e29d100c0
References:
https://snyk.io/vuln/SNYK-JAVA-ORGPYTHON-31451
Bugzilla
CVE-2014-4000 cacti: Multiple issues fixed in 1.0.0 version
bugzilla·2017-01-30·CVSS 8.8
CVE-2014-4000 [HIGH] CVE-2014-4000 cacti: Multiple issues fixed in 1.0.0 version
CVE-2014-4000 cacti: Multiple issues fixed in 1.0.0 version
Cacti upstream released a new version fixing multiple security issues. CVE-2016-2131 was already fixed once but it seems that the fix wasn't enough.
It is also fixing CVE-2014-4000 and some other potential security issues.
References:
http://www.cacti.net/release_notes_1_0_0.php
Discussion:
Created cacti tracking bugs for this issue:
Affects: epel-all [bug 1417605]
Affects: fedora-all [bug 1417604]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
Tenable
Oracle Critical Patch Update for October Contains 180 Fixes
blogs_tenable·2019-10-16
Oracle Critical Patch Update for October Contains 180 Fixes
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Oracle Critical Patch Update For April Contains 297 Fixes
blogs_tenable·2019-04-17
Oracle Critical Patch Update For April Contains 297 Fixes
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://bugs.jython.org/issue2454http://www.debian.org/security/2017/dsa-3893http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/105647https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=864859https://hg.python.org/jython/file/v2.7.1rc1/NEWShttps://hg.python.org/jython/rev/d06e29d100c0https://lists.apache.org/thread.html/0919ec1db20b1022f22b8e78f355667df74d6142b463ff17d03ad533%40%3Cdevnull.infra.apache.org%3Ehttps://security-tracker.debian.org/tracker/CVE-2016-4000https://security.gentoo.org/glsa/201710-28https://snyk.io/vuln/SNYK-JAVA-ORGPYTHON-31451https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttp://bugs.jython.org/issue2454http://www.debian.org/security/2017/dsa-3893http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/105647https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=864859https://hg.python.org/jython/file/v2.7.1rc1/NEWShttps://hg.python.org/jython/rev/d06e29d100c0https://lists.apache.org/thread.html/0919ec1db20b1022f22b8e78f355667df74d6142b463ff17d03ad533%40%3Cdevnull.infra.apache.org%3Ehttps://security-tracker.debian.org/tracker/CVE-2016-4000https://security.gentoo.org/glsa/201710-28https://snyk.io/vuln/SNYK-JAVA-ORGPYTHON-31451https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
2017-07-06
Published