CVE-2016-5003
27.10.2017, 18:29
The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serialized Java object in an <ex:serializable> element.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | ws-xmlrpc | 3.1.3 |
𝑥
= Vulnerable software versions
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| xmlrpc-client |
| ||
| xmlrpc-common |
| ||
| xmlrpc-javadoc |
| ||
| xmlrpc-server |
| ||
| xmlrpc3-client |
| ||
| xmlrpc3-client-devel |
| ||
| xmlrpc3-common |
| ||
| xmlrpc3-common-devel |
| ||
| xmlrpc3-javadoc |
| ||
| xmlrpc3-server |
| ||
| xmlrpc3-server-devel |
|
Common Weakness Enumeration
References