9.8
CVSSv3

CVE-2016-6809

Published: 06/04/2017 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 670
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Apache Tika prior to 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache tika

apache nutch 2.3.1

Vendor Advisories

Debian Bug report logs - #825501 CVE-2016-4434 Package: src:tika; Maintainer for src:tika is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Fri, 27 May 2016 10:03:02 UTC Severity: grave Tags: fixed-upstream, security, upstream Found in v ...
Apache Tika before 114 allows Java code execution for serialized objects embedded in MATLAB files The issue exists because Tika invokes JMatIO to do native deserialization ...