CVE-2016-7050

SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to execute arbitrary code.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
Affected Products (NVD)
VendorProductVersion
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_hpc_node
7.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_workstation
7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
resteasy
jessie
no-dsa
sid
3.6.2-2
fixed
resteasy3.0
bookworm
3.0.26-6
fixed
bullseye
3.0.26-2
fixed
jessie
no-dsa
sid
3.0.26-6
fixed
trixie
3.0.26-6
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
resteasy
artful
ignored
bionic
dne
cosmic
dne
disco
not-affected
eoan
not-affected
focal
not-affected
groovy
not-affected
hirsute
not-affected
impish
not-affected
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
precise
dne
trusty
dne
xenial
needed
yakkety
ignored
zesty
ignored
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
resteasy-base
RHEL 7
0:3.0.6-4.el7
fixed
resteasy-base-atom-provider
RHEL 7
0:3.0.6-4.el7
fixed
resteasy-base-client
RHEL 7
0:3.0.6-4.el7
fixed
resteasy-base-jackson-provider
RHEL 7
0:3.0.6-4.el7
fixed
resteasy-base-javadoc
RHEL 7
0:3.0.6-4.el7
fixed
resteasy-base-jaxb-provider
RHEL 7
0:3.0.6-4.el7
fixed
resteasy-base-jaxrs
RHEL 7
0:3.0.6-4.el7
fixed
resteasy-base-jaxrs-all
RHEL 7
0:3.0.6-4.el7
fixed
resteasy-base-jaxrs-api
RHEL 7
0:3.0.6-4.el7
fixed
resteasy-base-jettison-provider
RHEL 7
0:3.0.6-4.el7
fixed
resteasy-base-providers-pom
RHEL 7
0:3.0.6-4.el7
fixed
resteasy-base-resteasy-pom
RHEL 7
0:3.0.6-4.el7
fixed
resteasy-base-tjws
RHEL 7
0:3.0.6-4.el7
fixed