VulnerabilityModified
CVE-2016-2510
BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to execute arbitrary code via crafted serialized data, related to XThis.Handler.
HIGH 8.1EPSS 70.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 70.4%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to execute arbitrary code via crafted serialized data, related to XThis.Handler.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 70.43% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-19
- Affected
- beanshell/beanshell · debian/debian linux · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00056.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00078.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0539.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0540.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2035.htmlThird Party Advisory
- http://www.debian.org/security/2016/dsa-3504Third Party Advisory
- http://www.securityfocus.com/bid/84139Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1035440Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2923-1Third Party Advisory
- https://access.redhat.com/errata/RHSA-2016:1135Third Party Advisory
- https://access.redhat.com/errata/RHSA-2016:1376Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1545Third Party Advisory
- https://github.com/beanshell/beanshell/commit/1ccc66bb693d4e46a34a904db8eeff07808d2cedPatch, Third Party Advisory
- https://github.com/beanshell/beanshell/commit/7c68fde2d6fc65e362f20863d868c112a90a9b49Patch, Third Party Advisory
- https://github.com/beanshell/beanshell/releases/tag/2.0b6Patch, Third Party Advisory
- https://github.com/frohoff/ysoserial/pull/13Exploit, Third Party Advisory
- https://security.gentoo.org/glsa/201607-17Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.rsaconference.com/writable/presentations/file_upload/asd-f03-serial-killer-silently-pwning-your-java-endpoints.pdfExploit, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00056.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00078.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0539.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0540.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2035.htmlThird Party Advisory
- http://www.debian.org/security/2016/dsa-3504Third Party Advisory
- http://www.securityfocus.com/bid/84139Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1035440Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2923-1Third Party Advisory
- https://access.redhat.com/errata/RHSA-2016:1135Third Party Advisory
- https://access.redhat.com/errata/RHSA-2016:1376Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.