← Back to CVE List
Vulnerability Intelligence Report

CVE-2016-6330

The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-3737.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:10.62%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
redhat jboss_operations_network 3.0, 3.0.1, 3.1, 3.1.1, 3.1.2, 3.1.4, 3.2.0, 3.2.1, 3.2.2, 3.2.3, 3.3.1, 3.3.2, 3.3.3, 3.3.4, 3.3.5, 3.3.6

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
10.625%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2016-07-26T00:00:00
Published2016-09-27T15:00:00
Patch Date2016-08-21
Last Updated2024-08-06T01:29:18

LINK COPIED TO CLIPBOARD