CVE-2016-5983
HIGH 7.5EPSS 4.1%
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11, 9.0 before 9.0.0.2, and Liberty before 16.0.0.4 allows remote authenticated users to execute arbitrary Java code via a crafted serialized object.
- CVSS v3.0
- 7.5 HIGH
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P - EPSS
- 4.12% chance of exploitation in the next 30 days, 90th percentile
- Published
- 2016-10-05
- Updated
- 2024-08-06
Proof-of-concept exploits (1)
- BitWrecker/CVE-2016-59831★ · 2021-10-15