6.5
CVSSv2

CVE-2016-8648

Published: 01/08/2018 Updated: 12/02/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 580
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX operations. An attacker could use this flaw to execute remote code on the server as the user running the Java Virtual Machine if the target MBean contain deserialization gadgets in its classpath.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss a-mq 6.0.0

redhat jboss fuse 6.0.0

Vendor Advisories

It was found that the Karaf container used by Red Hat JBoss Fuse 6x, and Red Hat JBoss A-MQ 6x, deserializes objects passed to MBeans via JMX operations An attacker could use this flaw to execute remote code on the server as the user running the Java Virtual Machine if the target MBean contain deserialization gadgets in its classpath ...