Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.810965
Category:Web Servers
Title:Apache TomEE RCE Vulnerability
Summary:Apache TomEE is prone to a remote code execution (RCE); vulnerability.
Description:Summary:
Apache TomEE is prone to a remote code execution (RCE)
vulnerability.

Vulnerability Insight:
The flaw is due to an unspecified error in
EjbObjectInputStream class related to EJBd protocol.

Vulnerability Impact:
Successful exploitation will allow remote
attackers to execute arbitrary code via a crafted serialized object.

Affected Software/OS:
Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3.

Note: This issue only affects you if you rely on EJBd protocol
(proprietary remote EJB protocol). This one is not activated by
default on the 7.x series but it was on the 1.x ones.

Solution:
Upgrade to version 1.7.4 or 7.0.0-M3 or later.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-0779
BugTraq ID: 79204
http://www.securityfocus.com/bid/79204
Bugtraq: 20160315 [ANNOUNCE][CVE-2016-0779] Apache TomEE 1.7.4 and 7.0.0-M3 releases (Google Search)
http://www.securityfocus.com/archive/1/537806/100/0/threaded
http://packetstormsecurity.com/files/136256/Apache-TomEE-Patched.html
http://www.zerodayinitiative.com/advisories/ZDI-15-638
http://tomee-openejb.979440.n4.nabble.com/Document-resolved-vulnerability-CVE-2015-8581-td4678073.html
CopyrightCopyright (C) 2017 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.