Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.105765
Category:General
Title:RMI Java Deserialization RCE Vulnerability
Summary:The remote host is affected by a remote code execution (RCE); vulnerability.
Description:Summary:
The remote host is affected by a remote code execution (RCE)
vulnerability.

Vulnerability Insight:
The Apache Commons Collections (ACC) library is vulnerable to
insecure deserialization of data, which may result in arbitrary code execution. Java applications
that either directly use ACC, or contain ACC in their classpath, may be vulnerable to arbitrary
code execution.

Solution:
Ask the vendor for an update/workaround.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-3642
http://seclists.org/fulldisclosure/2016/Jun/29
http://seclists.org/fulldisclosure/2016/Jun/25
http://packetstormsecurity.com/files/137486/Solarwinds-Virtualization-Manager-6.3.1-Java-Deserialization.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-1487
http://support.lexmark.com/index?page=content&id=TE747&locale=EN&userlocale=EN_US
CopyrightCopyright (C) 2016 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.