CVE-2016-8653

Severity
5.3MEDIUM
EPSS
0.3%
top 42.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 1
Latest updateMay 13

Description

It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this flaw to launch a denial of service attack.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

CVEListV5red_hat/fuse6

🔴Vulnerability Details

2
GHSA
GHSA-9f74-frh8-4gmr: It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it2022-05-13
CVEList
CVE-2016-8653: It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it2018-08-01

📋Vendor Advisories

1
Red Hat
Fuse-6: JMX endpoint deserializes untrusted credentials.2016-11-25

🕵️Threat Intelligence

1
Krebs
Microsoft Issues Emergency Fix for IE Zero Day2018-12-19

💬Community

1
Bugzilla
CVE-2016-8653 Fuse-6: JMX endpoint deserializes untrusted credentials.2016-11-25
CVE-2016-8653 (MEDIUM CVSS 5.3) | It was found that the JMX endpoint | cvebase.io