VDB
WID-SEC-W-2024-3616
WID-SEC-W-2024-3616
PUBLISHED
CVSS 9.300000190734863 CRITICAL
JBoss Fuse ist ein Open Source Enterprise Service Bus (ESB). JBoss A-MQ ist eine Messaging-Plattform.
Risk Scores
CVSS v4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat JBoss A-MQ 6.3 | ||
| Red Hat JBoss Fuse 6.3 | ||
| Ubuntu Linux | ||
| Juniper Junos Space <20.1R1 | ||
| Juniper Junos Space 20.1R1 |
Exploit Intelligence
- 这是基于cve-2016-4437简单的漏洞复现代码 (github-poc)
- 1.验证CVE-2016-4437、2.解析rememberMe的文件和CBC加密的IV偏移 (github-poc)
- Python POC to Exploit CVE-2016-4437 Apache Shiro Deserialization Vulnerability Due to Hardcode Encryption Key (github-poc)
- 一个针对shiro反序列化漏洞(CVE-2016-4437)的快速利用工具/A simple tool targeted at shiro framework attacks with ysoserial. (github-poc)
- m3terpreter/CVE-2016-4437 (github-poc)
- CVE-2016-4437-Shiro反序列化爆破模块和key,命令执行,反弹shell的脚本 (github-poc)
- https://wid.cert-bund.de/.well-known/csaf/white/2016/wid-sec-w-2024-3616.json (circl)
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3616 (circl)
- https://rhn.redhat.com/errata/RHSA-2016-2036.html (circl)
- https://rhn.redhat.com/errata/RHSA-2016-2035.html (circl)
…and 2 more exploits
Timeline
- Oct 6, 2016 CVE Published
- Dec 5, 2024 CVE Updated
- Apr 10, 2026 Distribution Patch
References
- https://wid.cert-bund.de/.well-known/csaf/white/2016/wid-sec-w-2024-3616.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3616 advisory
- https://rhn.redhat.com/errata/RHSA-2016-2036.html url
- https://rhn.redhat.com/errata/RHSA-2016-2035.html url
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA11023 url
- https://ubuntu.com/security/notices/USN-7139-1 url