VDB
RHSA-2016:0118
RHSA-2016:0118
PUBLISHED
CVSS 9.600000381469727 CRITICAL
A flaw was discovered in the way applications using Groovy used the standard Java serialization mechanism. A remote attacker could use a specially crafted serialized object that would execute code directly when deserialized. All applications which rely on serialization and do not isolate the code which deserializes objects are subject to this vulnerability.
Risk Scores
CVSS 3.0
9.600000381469727
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Operations Network 3.3 |
Timeline
- Feb 3, 2016 CVE Published
- May 14, 2026 CVE Updated
- May 15, 2026 Distribution Patch
- May 15, 2026 Distribution Patch
- May 15, 2026 Security Advisory
- May 15, 2026 Security Advisory
- May 15, 2026 Security Advisory
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1187680 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1203799 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1206084 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1234991 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1243934 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1255196 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1269420 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1278215 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1293350 issue
- https://www.cve.org/CVERecord?id=CVE-2015-3253 advisory
- https://access.redhat.com/security/cve/CVE-2015-7501 advisory
- https://www.cve.org/CVERecord?id=CVE-2015-7501 advisory
- https://access.redhat.com/errata/RHSA-2016:0118 advisory
- https://access.redhat.com/security/updates/classification/#critical advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=em&downloadType=securityPatches&version=3.3 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1158947 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1231199 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1261907 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1277389 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1279330 issue
…and 8 more