1000
VMScore

CVE-2016-0779

CVSSv4: NA | CVSSv3: 9.8 | CVSSv2: 7.5 | VMScore: 1000 | EPSS: 0.09007 | KEV: Not Included
Published: 11/04/2017 Updated: 21/11/2024

Vulnerability Summary

The EjbObjectInputStream class in Apache TomEE prior to 1.7.4 and 7.x prior to 7.0.0-M3 allows remote malicious users to execute arbitrary code via a crafted serialized object.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache tomee

apache tomee 7.0.0