CVE-2016-6809
CRITICALApache Tika < 1.14 - Remote Code Execution via MATLAB File Deserialization
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2016-6809. PoCs published by dawetmaster, andikahilmy.
AI-analyzed exploit summary This repository appears to be a partial or incomplete snapshot of the Apache Tika project, specifically targeting CVE-2016-6809. It lacks exploit code or a detailed analysis of the vulnerability, instead containing only a subset of source files and a generic README.
Description
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
Exploits (2)
This repository appears to be a partial or incomplete snapshot of the Apache Tika project, specifically targeting CVE-2016-6809. It lacks exploit code or a detailed analysis of the vulnerability, instead containing only a subset of source files and a generic README.
This repository contains a snapshot of Apache Tika source code but lacks any exploit code or technical analysis related to CVE-2016-6809. It appears to be a partial clone of the Tika project without PoC or vulnerability details.
References (8)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H