cbcvebase.
CVE-2016-6330
published 2016-09-27

CVE-2016-6330: The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote attackers…

PriorityP262critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
10.63%
95.3th percentile
The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-3737.

Affected

16 ranges
VendorProductVersion rangeFixed in
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector is a crafted HTTP request targeting JBoss Operations Network (JON) server when SSL authentication is NOT configured for JON server/agent communication, leading to remote code execution via message deserialization.
  • This is an incomplete fix for CVE-2016-3737; detection logic or rules written for CVE-2016-3737 deserialization attacks against JON should be re-evaluated, as the original patch in JON 3.3.6 did not fully remediate the attack surface.
  • Absence of SSL client certificate authentication on JON server/agent communication channel is a prerequisite for exploitation; monitor for unauthenticated or non-SSL JON agent connections as a detection signal.
  • ·The Red Hat security advisory for JON 3.3.6 incorrectly stated CVE-2016-3737 was fixed; CVE-2016-6330 tracks the residual exposure. Any asset still running JON 3.3.6 without SSL auth configured should be treated as unpatched.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:N/C:P/I:P/A:C
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.