9.8

CVE-2016-0360

IBM Websphere MQ JMS 7.0.1, 7.1, 7.5, 8.0, and 9.0 client provides classes that deserialize objects from untrusted sources which could allow a malicious user to execute arbitrary Java code by adding vulnerable classes to the classpath. IBM Reference #: 1983457.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Websphere Mq Jms Version 7.0.1
Ibm ≫ Websphere Mq Jms Version 7.1
Ibm ≫ Websphere Mq Jms Version 7.5
Ibm ≫ Websphere Mq Jms Version 8.0
Ibm ≫ Websphere Mq Jms Version 9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.81% 0.847
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

http://www-01.ibm.com/support/docview.wss?uid=swg21983457
Vendor Advisory
http://www.securityfocus.com/bid/95317
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1037561