Deserialization of untrusted data in XML-RPC - CVE-2016-5003

 

Deserialization of untrusted data in XML-RPC - CVE-2016-5003

Published: June 4, 2018 / Updated: June 1, 2023


Vulnerability identifier: #VU13176
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5003
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper deserialization of untrusted Java objects. A remote attacker can send a request that submits a malicious serialized Java object in an <ex:serializable> element and execute arbitrary code with elevated privileges.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

XML-RPC
Gentoo Linux
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux EUS Compute Node
Fedora
Red Hat Virtualization
Zoho ManageEngine OpManager
xmlrpc

How to mitigate CVE-2016-5003

Install update from vendor's website.

XML-RPC - update to 3.1.4
Zoho ManageEngine OpManager - update to 12.7 127104
xmlrpc - addressed in versions 3.1.3-20.fc26, 3.1.3-20.fc27, 3.1.3-20.fc28

External References

Related Security Bulletins