CVE-2016-6793
published 2017-07-17CVE-2016-6793: The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop) and…
PriorityP354critical9.1CVSS 3.0
AVNACLPRNUINSUCNIHAH
EPSS
8.46%
94.4th percentile
The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and delete files with the permissions of DiskFileItem, and if running on a Java VM before 1.3.1, execute arbitrary code via a crafted serialized Java object.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | wicket | >= 1.5.0 < 1.5.17 | 1.5.17 |
| apache | wicket | >= 6.0.0 < 6.25.0 | 6.25.0 |
CVSS provenance
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Tenable
[R4] Apache Wicket DiskFileItem Java Deserialization Remote File Manipulation
blogs_tenable·2016-08-12
[R4] Apache Wicket DiskFileItem Java Deserialization Remote File Manipulation
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
arXiv
An In-depth Study of Java Deserialization Remote-Code Execution Exploits and Vulnerabilities
arxiv_fulltext·2022-08-17
An In-depth Study of Java Deserialization Remote-Code Execution Exploits and Vulnerabilities
An In-depth Study of Java Deserialization Remote-Code Execution Exploits and Vulnerabilities
[Imen Sayar]Imen Sayar^
[email protected]
University of Toulouse
Blagnac
France
31070
^ Part of this research was conducted when Imen Sayar was at the University of Luxembourg
[Alexandre Bartel]Alexandre Bartel^*
[email protected]
Umeå University
MIT-Huset
Umeå
Sweden
^*Part of this research was conducted when Alexandre Bartel was at the University of Luxembourg and the University of Copenhagen.
Eric Bodden
[email protected]
Paderborn University
Paderborn
Germany
Yves Le Traon
[email protected]
University of Luxembourg
6, rue Richard Coudenhove-Kalergi
Kirchberg Campus
Luxembourg
L-1359
## Abstract
Nowadays, an increasing number of applications uses deserializatio
http://www.openwall.com/lists/oss-security/2016/12/31/1http://www.securityfocus.com/archive/1/539975/100/0/threadedhttp://www.securityfocus.com/bid/95168http://www.securitytracker.com/id/1037541https://wicket.apache.org/news/2016/12/31/cve-2016-6793.htmlhttps://www.tenable.com/security/research/tra-2016-23http://www.openwall.com/lists/oss-security/2016/12/31/1http://www.securityfocus.com/archive/1/539975/100/0/threadedhttp://www.securityfocus.com/bid/95168http://www.securitytracker.com/id/1037541https://wicket.apache.org/news/2016/12/31/cve-2016-6793.htmlhttps://www.tenable.com/security/research/tra-2016-23
2017-07-17
Published