CVE-2016-2510
Last modified
CVE-2016-2510 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to execute arbitrary code via crafted serialized data, related to XThis.Handler.. EPSS estimates a 70.43% chance of exploitation in the next 30 days.
Description
BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to execute arbitrary code via crafted serialized data, related to XThis.Handler.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Beanshell | Beanshell | 1.0 | — |
| Beanshell | Beanshell | 2.0 | Beta1 |
| Debian | Debian Linux | 7.0 | — |
| Debian | Debian Linux | 8.0 | — |
| Canonical | Ubuntu Linux | 12.04 | — |
| Canonical | Ubuntu Linux | 14.04 | — |
| Canonical | Ubuntu Linux | 15.10 | — |
References
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00056.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00078.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0539.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0540.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2035.htmlThird Party Advisory
- http://www.debian.org/security/2016/dsa-3504Third Party Advisory
- http://www.securityfocus.com/bid/84139Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1035440Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2923-1Third Party Advisory
- https://access.redhat.com/errata/RHSA-2016:1135Third Party Advisory
- https://access.redhat.com/errata/RHSA-2016:1376Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1545Third Party Advisory
- https://github.com/beanshell/beanshell/commit/1ccc66bb693d4e46a34a904db8eeff07808d2cedPatch, Third Party Advisory
- https://github.com/beanshell/beanshell/commit/7c68fde2d6fc65e362f20863d868c112a90a9b49Patch, Third Party Advisory
- https://github.com/beanshell/beanshell/releases/tag/2.0b6Patch, Third Party Advisory
- https://github.com/frohoff/ysoserial/pull/13Exploit, Third Party Advisory
- https://security.gentoo.org/glsa/201607-17Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00056.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00078.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0539.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0540.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2035.htmlThird Party Advisory
- http://www.debian.org/security/2016/dsa-3504Third Party Advisory
- http://www.securityfocus.com/bid/84139Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1035440Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2923-1Third Party Advisory
- https://access.redhat.com/errata/RHSA-2016:1135Third Party Advisory
- https://access.redhat.com/errata/RHSA-2016:1376Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1545Third Party Advisory
- https://github.com/beanshell/beanshell/commit/1ccc66bb693d4e46a34a904db8eeff07808d2cedPatch, Third Party Advisory
- https://github.com/beanshell/beanshell/commit/7c68fde2d6fc65e362f20863d868c112a90a9b49Patch, Third Party Advisory
- https://github.com/beanshell/beanshell/releases/tag/2.0b6Patch, Third Party Advisory
- https://github.com/frohoff/ysoserial/pull/13Exploit, Third Party Advisory
- https://security.gentoo.org/glsa/201607-17Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-2510?
How severe is CVE-2016-2510?
How do I fix CVE-2016-2510?
Are you affected by CVE-2016-2510?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
