CVE-2016-6330
published 2016-09-27CVE-2016-6330: The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote attackers…
PriorityP262critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
10.63%
95.3th percentile
The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-3737.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit vector is a crafted HTTP request targeting JBoss Operations Network (JON) server when SSL authentication is NOT configured for JON server/agent communication, leading to remote code execution via message deserialization. ↗
- →This is an incomplete fix for CVE-2016-3737; detection logic or rules written for CVE-2016-3737 deserialization attacks against JON should be re-evaluated, as the original patch in JON 3.3.6 did not fully remediate the attack surface. ↗
- →Absence of SSL client certificate authentication on JON server/agent communication channel is a prerequisite for exploitation; monitor for unauthenticated or non-SSL JON agent connections as a detection signal. ↗
- ·The Red Hat security advisory for JON 3.3.6 incorrectly stated CVE-2016-3737 was fixed; CVE-2016-6330 tracks the residual exposure. Any asset still running JON 3.3.6 without SSL auth configured should be treated as unpatched. ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:N/C:P/I:P/A:C
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JON: incomplete fix for CVE-2016-3737
vendor_redhat·2016-08-22·CVSS 9.8
CVE-2016-6330 [CRITICAL] JON: incomplete fix for CVE-2016-3737
JON: incomplete fix for CVE-2016-3737
The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-3737.
Mitigation: Apply the configuration changes described in the documentation here: https://access.redhat.com/documentation/en-US/Red_Hat_JBoss_Operations_Network/3.3/html/Admin_and_Config/JBoss_ON_and_SSL-Authentication.html
For more information, refer to https://access.redhat.com/articles/2570101.
Package: Core Server (Red Hat JBoss Operations Network 3) - Will not fix
GHSA
GHSA-hpgf-x5r5-6h89: The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote at
ghsa_unreviewed·2022-05-17·CVSS 9.8
CVE-2016-6330 [CRITICAL] CWE-502 GHSA-hpgf-x5r5-6h89: The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote at
The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-3737.
No detection rules found.
No public exploits indexed.
2016-09-27
Published