cbcvebase.
CVE-2016-7050
published 2017-06-08

CVE-2016-7050: SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat…

PriorityP261critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.85%
91.1th percentile
SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to execute arbitrary code.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianresteasy< resteasy 3.0.18-1 (sid)resteasy 3.0.18-1 (sid)
debianresteasy3.0< resteasy 3.0.18-1 (sid)resteasy 3.0.18-1 (sid)
redhatenterprise_linux_desktop
redhatenterprise_linux_hpc_node
redhatenterprise_linux_server
redhatenterprise_linux_workstation
redhatresteasy>= 0 < 3.0.6-3ubuntu0.1~esm13.0.6-3ubuntu0.1~esm1

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered when RESTEasy is forced to parse a request using SerializableProvider, enabling deserialization of untrusted data. Detect HTTP requests with Content-Type or Accept headers indicating Java serialized object payloads (e.g., application/x-java-serialized-object) directed at RESTEasy endpoints.
  • SerializableProvider is enabled by default in RESTEasy 3 before 3.0.15.Final; audit deployments for presence of this provider and monitor for unexpected deserialization activity in application logs.
  • Exploitation results in arbitrary code execution with the permissions of the application using RESTEasy; monitor for anomalous process spawning from Java application server processes on affected RHEL 7 systems.
  • ·RESTEasy as shipped in Red Hat JBoss Enterprise Application Platform 6, JBoss Enterprise Application Platform 7, and JBoss Fuse 6 is NOT affected by this CVE; only the resteasy package in Red Hat Enterprise Linux 7 (Desktop, HPC Node, Server, Workstation) is affected.
  • ·The Debian fix was applied in resteasy version 3.0.18-1 (sid); the vulnerable version threshold is RESTEasy 3 before 3.0.15.Final.
  • ·JBoss Fuse 6 initially appeared to use a vulnerable version of resteasy but was determined not affected because it is used only as a RESTful webservice client (Fabric8/Support Webapp), not a server-side provider.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.