CVE-2016-0779
CVE-2016-0779
The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted serialized object.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://packetstormsecurity.com/files/136256/Apache-TomEE-Patched.htmlhttp://tomee.apache.org/security/tomee.htmlhttp://tomee-openejb.979440.n4.nabble.com/Document-resolved-vulnerability-CVE-2015-8581-td4678073.htmlhttp://www.securityfocus.com/archive/1/537806/100/0/threadedhttp://www.securityfocus.com/bid/79204http://www.zerodayinitiative.com/advisories/ZDI-15-638