CVE-2016-6814

Related Vulnerabilities: CVE-2016-6814  

It was found that a flaw in Apache groovy library allows remote code execution wherever deserialization occurs in the application. It is possible for an attacker to craft a special serialized object that will execute code directly when deserialized. All applications which rely on serialization and do not isolate the code which deserializes objects are subject to this vulnerability.

It was found that a flaw in Apache groovy library allows remote code execution wherever deserialization occurs in the application. It is possible for an attacker to craft a special serialized object that will execute code directly when deserialized. All applications which rely on serialization and do not isolate the code which deserializes objects are subject to this vulnerability.

Find out more about CVE-2016-6814 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This issue affects the versions of groovy as shipped with Red Hat Satellite 6.0 and 6.1. Red Hat Satellite 6.2 and later do not ship groovy, as such they are not affected by this vulnerability.

CVSS v3 metrics

CVSS3 Base Score 9.6
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Changed
Confidentiality High
Integrity Impact High
Availability Impact High

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss Fuse 6.3 RHSA-2017:0868 2017-04-03
Red Hat Software Collections for Red Hat Enterprise Linux 6 (rh-maven33-groovy) RHSA-2017:2596 2017-09-05
Red Hat Enterprise Linux 7 (groovy) RHSA-2017:2486 2017-08-17
Red Hat JBoss A-MQ 6.3 RHSA-2017:0868 2017-04-03
Red Hat Software Collections for Red Hat Enterprise Linux 7 (rh-maven33-groovy) RHSA-2017:2596 2017-09-05

Affected Packages State

Platform Package State
Red Hat Satellite 6 groovy Not affected
Red Hat OpenShift Enterprise 2 jenkins Will not fix
Red Hat JBoss Portal 5 groovy Under investigation
Red Hat JBoss Operations Network 3 groovy Not affected
Red Hat JBoss Fuse Service Works 6 camel Affected
Red Hat JBoss Enterprise SOA Platform 5 groovy Will not fix
Red Hat JBoss EAP 5 groovy Will not fix
Red Hat JBoss Data Virtualization 6 groovy Affected
Red Hat JBoss BRMS 5 groovy Will not fix
RHEV Manager 3 jasperreports-server-pro Will not fix