CVE-2016-7050

Severity
9.8CRITICAL
EPSS
0.6%
top 31.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 8
Latest updateJul 10

Description

SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to execute arbitrary code.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

🔴Vulnerability Details

3
GHSA
GHSA-m2g5-gpqx-rwvw: SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Re2022-05-17
CVEList
CVE-2016-7050: SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Re2017-06-08
OSV
CVE-2016-7050: SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Re2017-06-08

📋Vendor Advisories

3
Ubuntu
RESTEasy vulnerabilities2025-07-10
Red Hat
RESTEasy: SerializableProvider enabled by default and deserializes untrusted data2016-09-23
Debian
CVE-2016-7050: resteasy - SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat ...2016

💬Community

2
Bugzilla
CVE-2016-7050 RESTEasy: SerializableProvider enabled by default and deserializes untrusted data2016-09-22
Bugzilla
CVE-2016-7050 resteasy: SerializableProvider in RESTEasy 3 before 3.0.15.Final is enabled by default and deserializes untrusted data [fedora-all]2016-09-22