9
CVSSv2

CVE-2016-3737

Published: 02/08/2016 Updated: 03/11/2017
CVSS v2 Base Score: 9 | Impact Score: 8.5 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 801
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:C

Vulnerability Summary

The server in Red Hat JBoss Operations Network (JON) prior to 3.3.6 allows remote malicious users to execute arbitrary code via a crafted HTTP request, related to message deserialization.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss operations network

Vendor Advisories

It was discovered that sending specially crafted HTTP request to the JON server would allow deserialization of that message without authentication An attacker could use this flaw to cause remote code execution ...