vulnerability
Oracle Linux: CVE-2016-7050: ELSA-2016-2604: resteasy-base security and bug fix update (IMPORTANT)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:N/AC:L/Au:N/C:P/I:P/A:P) | Sep 23, 2016 | Nov 9, 2016 | Dec 3, 2025 |
Severity
7
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Sep 23, 2016
Added
Nov 9, 2016
Modified
Dec 3, 2025
Description
SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to execute arbitrary code.
It was discovered that under certain conditions RESTEasy could be forced to parse a request with SerializableProvider, resulting in deserialization of potentially untrusted data. An attacker could possibly use this flaw execute arbitrary code with the permissions of the application using RESTEasy.
It was discovered that under certain conditions RESTEasy could be forced to parse a request with SerializableProvider, resulting in deserialization of potentially untrusted data. An attacker could possibly use this flaw execute arbitrary code with the permissions of the application using RESTEasy.
Solutions
oracle-linux-upgrade-resteasy-baseoracle-linux-upgrade-resteasy-base-atom-provideroracle-linux-upgrade-resteasy-base-clientoracle-linux-upgrade-resteasy-base-jackson-provideroracle-linux-upgrade-resteasy-base-javadocoracle-linux-upgrade-resteasy-base-jaxb-provideroracle-linux-upgrade-resteasy-base-jaxrsoracle-linux-upgrade-resteasy-base-jaxrs-alloracle-linux-upgrade-resteasy-base-jaxrs-apioracle-linux-upgrade-resteasy-base-jettison-provideroracle-linux-upgrade-resteasy-base-providers-pomoracle-linux-upgrade-resteasy-base-resteasy-pomoracle-linux-upgrade-resteasy-base-tjws
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.