Lucene search

K
redhatcveRedhat.comRH:CVE-2016-6330
HistoryAug 22, 2016 - 1:18 a.m.

CVE-2016-6330

2016-08-2201:18:41
redhat.com
access.redhat.com
11

0.012 Low

EPSS

Percentile

85.2%

The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-3737.

Mitigation

Apply the configuration changes described in the documentation here: <https://access.redhat.com/documentation/en-US/Red_Hat_JBoss_Operations_Network/3.3/html/Admin_and_Config/JBoss_ON_and_SSL-Authentication.html&gt;
For more information, refer to <https://access.redhat.com/articles/2570101&gt;.

0.012 Low

EPSS

Percentile

85.2%