VulnerabilityModified
CVE-2016-5003
The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serialized Java object in an <ex:serializable> element.
CRITICAL 9.8EPSS 14.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.9%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serialized Java object in an <ex:serializable> element.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 14.88% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- apache/ws-xmlrpc
- Source
- secalert@redhat.com
References
- http://www.openwall.com/lists/oss-security/2016/07/12/5Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2020/01/16/1
- http://www.openwall.com/lists/oss-security/2020/01/24/2
- http://www.securityfocus.com/bid/91736Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/91738Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036294Third Party Advisory, VDB Entry
- https://0ang3el.blogspot.ru/2016/07/beware-of-ws-xmlrpc-library-in-your.htmlExploit, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1779
- https://access.redhat.com/errata/RHSA-2018:1780
- https://access.redhat.com/errata/RHSA-2018:1784
- https://access.redhat.com/errata/RHSA-2018:2317
- https://access.redhat.com/errata/RHSA-2018:3768
- https://exchange.xforce.ibmcloud.com/vulnerabilities/115043Third Party Advisory, VDB Entry
- https://security.gentoo.org/glsa/202401-26
- http://www.openwall.com/lists/oss-security/2016/07/12/5Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2020/01/16/1
- http://www.openwall.com/lists/oss-security/2020/01/24/2
- http://www.securityfocus.com/bid/91736Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/91738Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036294Third Party Advisory, VDB Entry
- https://0ang3el.blogspot.ru/2016/07/beware-of-ws-xmlrpc-library-in-your.htmlExploit, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1779
- https://access.redhat.com/errata/RHSA-2018:1780
- https://access.redhat.com/errata/RHSA-2018:1784
- https://access.redhat.com/errata/RHSA-2018:2317
- https://access.redhat.com/errata/RHSA-2018:3768
- https://exchange.xforce.ibmcloud.com/vulnerabilities/115043Third Party Advisory, VDB Entry
- https://security.gentoo.org/glsa/202401-26
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.