CVE-2016-3690
CRITICALJBoss Enterprise Application Platform 4.x and 5.x - Remote Code Execution via PooledInvokerServlet Deserialization
Title source: manualDescription
The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.
References (4)
Core 4
Core References
Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1327037
Mitigation, Vendor Advisory x_refsource_misc
https://access.redhat.com/solutions/45530
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/99079
Mitigation, Vendor Advisory x_refsource_confirm
https://access.redhat.com/solutions/178393
Scores
CVSS v3
9.8
EPSS
0.0524
EPSS Percentile
91.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-502
Status
published
Products (7)
redhat/jboss_enterprise_application_platform
4.2.0
redhat/jboss_enterprise_application_platform
4.3.0
redhat/jboss_enterprise_application_platform
5.0.0
redhat/jboss_enterprise_application_platform
5.1.0
redhat/jboss_enterprise_application_platform
5.1.1
redhat/jboss_enterprise_application_platform
5.1.2
redhat/jboss_enterprise_application_platform
5.2.0
Published
Jun 08, 2017
Tracked Since
Feb 18, 2026