CVE-2016-8648
published 2018-08-01CVE-2016-8648: It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX operations. An…
PriorityP341high7.2CVSS 3.0
AVNACLPRHUINSUCHIHAH
EPSS
2.00%
78.6th percentile
It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX operations. An attacker could use this flaw to execute remote code on the server as the user running the Java Virtual Machine if the target MBean contain deserialization gadgets in its classpath.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache_software_foundation | karaf | — | — |
| redhat | jboss_a-mq | — | — |
| redhat | jboss_fuse | — | — |
CVSS provenance
nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Karaf JMX Console RCE during deserialization
vendor_redhat·2016-11-24·CVSS 7.2
CVE-2016-8648 [HIGH] CWE-502 Karaf JMX Console RCE during deserialization
Karaf JMX Console RCE during deserialization
It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX operations. An attacker could use this flaw to execute remote code on the server as the user running the Java Virtual Machine if the target MBean contain deserialization gadgets in its classpath.
It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX operations. An attacker could use this flaw to execute remote code on the server as the user running the Java Virtual Machine if the target MBean contain deserialization gadgets in its classpath.
Mitigation: In order to exploit this issue you need to have credentials
GHSA
GHSA-rcmq-ww8v-3mxm: It was found that the Karaf container used by Red Hat JBoss Fuse 6
ghsa_unreviewed·2022-05-13
CVE-2016-8648 [HIGH] CWE-502 GHSA-rcmq-ww8v-3mxm: It was found that the Karaf container used by Red Hat JBoss Fuse 6
It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX operations. An attacker could use this flaw to execute remote code on the server as the user running the Java Virtual Machine if the target MBean contain deserialization gadgets in its classpath.
No detection rules found.
No public exploits indexed.
2018-08-01
Published