CVE-2016-3690
08.06.2017, 18:29
The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | jboss_enterprise_application_platform | 4.2.0 |
redhat | jboss_enterprise_application_platform | 4.3.0 |
redhat | jboss_enterprise_application_platform | 5.0.0 |
redhat | jboss_enterprise_application_platform | 5.1.0 |
redhat | jboss_enterprise_application_platform | 5.1.1 |
redhat | jboss_enterprise_application_platform | 5.1.2 |
redhat | jboss_enterprise_application_platform | 5.2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References