The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-3737.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://www.tenable.com/security/research/tra-2016-22 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1368864 | issue tracking vendor advisory mitigation |
http://www.securityfocus.com/bid/92568 | vdb entry third party advisory |