CVE-2016-7050
Vulnerability Summary
Timeline
Description
SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to execute arbitrary code.
CVSS Metrics
- v3.0•CRITICAL•Score: 9.8CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- v3.0•CRITICAL•Score: 9CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- v2.0•HIGH•Score: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS Trends
Current EPSS score: 5.31%• Percentile: 92%
Techniques & Countermeasures
- CWE-502•Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Affected Systems
- redhat•enterprise_linux_desktop
7.0
- redhat•enterprise_linux_hpc_node
7.0
- redhat•enterprise_linux_server
7.0
- redhat•enterprise_linux_workstation
7.0
- redhat•resteasy-base
< 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7
- redhat•resteasy-base-atom-provider
< 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7
- redhat•resteasy-base-client
< 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7
- redhat•resteasy-base-jackson-provider
< 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7
- redhat•resteasy-base-javadoc
< 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7
- redhat•resteasy-base-jaxb-provider
< 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7
- redhat•resteasy-base-jaxrs
< 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7
- redhat•resteasy-base-jaxrs-all
< 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7
- redhat•resteasy-base-jaxrs-api
< 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7
- redhat•resteasy-base-jettison-provider
< 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7
- redhat•resteasy-base-providers-pom
< 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7
- redhat•resteasy-base-resteasy-pom
< 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7
- redhat•resteasy-base-tjws
< 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7 | < 0:3.0.6-4.el7
References (11)
- http://rhn.redhat.com/errata/RHSA-2016-2604.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1378613
- https://access.redhat.com/errata/RHSA-2016:2604
- https://access.redhat.com/security/updates/classification/#important
- https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/7.3_Release_Notes/index.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1280539
- https://bugzilla.redhat.com/show_bug.cgi?id=1357624
- https://security.access.redhat.com/data/csaf/v2/advisories/2016/rhsa-2016_2604.json
- https://access.redhat.com/security/cve/CVE-2016-7050
- https://www.cve.org/CVERecord?id=CVE-2016-7050
- https://nvd.nist.gov/vuln/detail/CVE-2016-7050