CVE-2016-7050
critical
CVSS v3
9.8
CVSS v2
7.5
VIR risk
9.8
Description
SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to execute arbitrary code.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-7050
Vendor advisory: cve@mitre.org — https://bugzilla.redhat.com/show_bug.cgi?id=1378613
Vendor advisory: cve@mitre.org — http://rhn.redhat.com/errata/RHSA-2016-2604.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| rhel | 7.0 | affected | |
| debian | bookworm | fixed | 0 |
| debian | bullseye | fixed | 0 |
| debian | forky | fixed | 0 |
| debian | trixie | fixed | 0 |
| debian | sid | fixed | 3.0.18-1 |
References
CWEs
CWE-502
Verify integrity in audit chain (admin only). AS-IS.