CVE-2016-5062

CRITICAL

Aternity <9.0.1 - RCE

Title source: llm
STIX 2.1

Description

The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL loading of Java MBeans, which allows remote attackers to execute arbitrary Java code by registering MBeans.

Scores

CVSS v3 9.8
EPSS 0.0048
EPSS Percentile 65.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-669
Status published
Products (1)
aternity/aternity < 9.0
Published Sep 29, 2016
Tracked Since Feb 18, 2026