CVE-2016-8653
published 2018-08-01CVE-2016-8653: It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this flaw to…
PriorityP427medium5.3CVSS 3.0
AVNACLPRNUINSUCNINAL
EPSS
1.93%
77.8th percentile
It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this flaw to launch a denial of service attack.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | fuse | — | — |
| redhat | jboss_a-mq | — | — |
| redhat | jboss_fuse | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Fuse-6: JMX endpoint deserializes untrusted credentials.
vendor_redhat·2016-11-25·CVSS 5.3
CVE-2016-8653 [MEDIUM] CWE-502 Fuse-6: JMX endpoint deserializes untrusted credentials.
Fuse-6: JMX endpoint deserializes untrusted credentials.
It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this flaw to launch a denial of service attack.
Package: Karaf (Red Hat JBoss A-MQ 6) - Affected
Package: Karaf (Red Hat JBoss Fuse 6) - Affected
GHSA
GHSA-9f74-frh8-4gmr: It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it
ghsa_unreviewed·2022-05-13
CVE-2016-8653 [MEDIUM] CWE-502 GHSA-9f74-frh8-4gmr: It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it
It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this flaw to launch a denial of service attack.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-8653 Fuse-6: JMX endpoint deserializes untrusted credentials.
bugzilla·2016-11-25·CVSS 5.3
CVE-2016-8653 [MEDIUM] CVE-2016-8653 Fuse-6: JMX endpoint deserializes untrusted credentials.
CVE-2016-8653 Fuse-6: JMX endpoint deserializes untrusted credentials.
It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this flaw to launch a denial of service attack.
Discussion:
Acknowledgments:
Name: Jason Shepherd (Red Hat)
Bugzilla
CVE-2016-8735 tomcat: Remote code execution vulnerability in JmxRemoteLifecycleListener
bugzilla·2016-11-22·CVSS 9.8
CVE-2016-8735 [CRITICAL] CVE-2016-8735 tomcat: Remote code execution vulnerability in JmxRemoteLifecycleListener
CVE-2016-8735 tomcat: Remote code execution vulnerability in JmxRemoteLifecycleListener
The JmxRemoteLifecycleListener was not updated to take account of Oracle's fix for CVE-2016-3427. Therefore, Tomcat installations using this listener remained vulnerable to a similar remote code execution vulnerability. This issue has been rated as important rather than critical due to the small number of installations using this listener and that it would be highly unusual for the JMX ports to be accessible to an attacker even when the listener is used.
Affects: 6.0.0 to 6.0.47, 7.0.0 to 7.0.72, 8.0.0.RC1 to 8.0.38, 8.5.0 to 8.5.6
Upstream patches:
Tomcat 6.0.48: https://svn.apache.org/viewvc?view=rev&rev=1767684
Tomcat 7.0.73: http://svn.apache.org/viewvc?view=rev&rev=1767676
Tomcat 8.0.39: http:/
Krebs
Microsoft Issues Emergency Fix for IE Zero Day
blogs_krebs·2018-12-19·CVSS 7.5
CVE-2018-8653 [HIGH] Microsoft Issues Emergency Fix for IE Zero Day
Microsoft today released an emergency software patch to plug a critical security hole in its Internet Explorer (IE) Web browser that attackers are already using to break into Windows computers.
The software giant said it learned about the weakness ( CVE-2018-8653 ) after receiving a report from Google about a new vulnerability being used in targeted attacks.
Satnam Narang , senior research engineer at Tenable , said the vulnerability affects the following installations of IE: Internet Explorer 11 from Windows 7 to Windows 10 as well as Windows Server 2012, 2016 and 2019; IE 9 on Windows Server 2008; and IE 10 on Windows Server 2012.
“As the flaw is being actively exploited in the wild, users are urged to update their systems as soon as possible to reduce the risk of compromise,” Narang
2018-08-01
Published