← back
CVE-2016-9606CWE-20

CVE-2016-9606

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 6.1%
exploitation probability
6.1%top 7% of all CVEs
observed exploitation
nono source reports it
JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitrary code with RESTEasy application permissions.
Affected products
Red Hat, Inc. · RESTEasy