CVE-2016-8648

HIGH

Red Hat JBoss Fuse/J-A-MQ 6.x - Code Injection

Title source: llm

Description

It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX operations. An attacker could use this flaw to execute remote code on the server as the user running the Java Virtual Machine if the target MBean contain deserialization gadgets in its classpath.

Scores

CVSS v3 7.2
EPSS 0.0051
EPSS Percentile 66.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (2)

redhat/jboss_a-mq
redhat/jboss_fuse

Timeline

Published Aug 01, 2018
Tracked Since Feb 18, 2026