Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-6814

39
FAUCET Score

CVE-2016-6814 is a critical deserialization vulnerability affecting Codehaus Groovy versions 1.7.0 to 2.4.3 and Apache Groovy versions 2.4.4 to 2.4.7, including related Red Hat products. This flaw allows an unauthenticated attacker to execute arbitrary code remotely by crafting a malicious serialized object that is processed by an application using standard Java serialization mechanisms. With a CVSS score of 9.8, this vulnerability presents a severe risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While no public exploit intelligence (Metasploit, Nuclei, ExploitDB) or active exploitation is indicated, and community discussion is minimal, the high EPSS score suggests a significant potential for future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.7.0, <= 2.4.3CPE matchmatch criteria
cpe:2.3:a:apache:groovy:*:*:*:*:*:*:*:*
>= 2.4.4, <= 2.4.7CPE matchmatch criteria
cpe:2.3:a:apache:groovy:*:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

9.8CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
17.24%
Probability of exploitation in next 30 days
EPSS Percentile
96.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.1724 is in the 93rd percentile among its peer group of 36,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (19)

mavenpatch availablevia ghsa
Product: org.codehaus.groovy:groovy-allFixed in: 2.4.8
mavenpatch availablevia ghsa
Product: org.codehaus.groovy:groovyFixed in: 2.4.8
redhatpatch availablevia redhat_api
Product: Red Hat JBoss A-MQ 6.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Data Virtualization 6.3Fixed in: groovy
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Fuse 6.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: rh-maven33-groovy-0:1.8.9-7.19.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSFixed in: rh-maven33-groovy-0:1.8.9-7.19.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-maven33-groovy-0:1.8.9-7.19.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUSFixed in: rh-maven33-groovy-0:1.8.9-7.19.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: groovy-0:1.8.9-8.el7_4
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Portal 5Fixed in: groovy
redhatno patchvia redhat_api
Product: Red Hat JBoss Fuse Service Works 6Fixed in: camel
redhatno patchvia redhat_api
Product: Red Hat JBoss A-MQ 6Fixed in: groovy
redhatno patchvia redhat_api
Product: Red Hat JBoss Fuse 6Fixed in: camel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Virtualization 3Fixed in: jasperreports-server-pro
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Enterprise 2Fixed in: jenkins
redhatend of lifevia redhat_api
Product: Red Hat JBoss BRMS 5Fixed in: groovy
redhatend of lifevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 5Fixed in: groovy
redhatend of lifevia redhat_api
Product: Red Hat JBoss SOA Platform 5Fixed in: groovy

Vendor Advisories (2)

mavenGHSA-xphj-m9cc-8fmqcritical

Deserialization of Untrusted Data in Groovy

May 13, 2022
redhatCVE-2016-6814Important

Groovy: Remote code execution via deserialization

Jan 14, 2017

References

mail-archives.apache.org / mod_mbox/www-announce/201701.mbox/%3CCADRx3PMZ2hBCGDTY35zYXFGaDnjAs0tc5-upaVs6QN2sYUejyA%40mail.gmail.com%3E
PatchVendor Advisory
rhn.redhat.com / errata/RHSA-2017-0272.html
Broken Link
access.redhat.com / errata/RHSA-2017:0868
Broken Link
access.redhat.com / errata/RHSA-2017:2486
Third Party Advisory
access.redhat.com / errata/RHSA-2017:2596
Third Party Advisory
security.gentoo.org / glsa/202003-01
oracle.com / security-alerts/cpujan2020.html
oracle.com / security-alerts/cpujul2020.html
oracle.com / technetwork/security-advisory/cpujan2019-5072801.html
oracle.com / technetwork/security-advisory/cpujul2019-5072835.html
oracle.com / technetwork/security-advisory/cpuoct2019-5072832.html
oracle.com / technetwork/security-advisory/cpuapr2018-3678067.html
oracle.com / technetwork/security-advisory/cpujul2018-4258247.html
oracle.com / technetwork/security-advisory/cpuoct2018-4428296.html
securityfocus.com / bid/95429
Third Party AdvisoryVDB Entry
securitytracker.com / id/1039600
Third Party AdvisoryVDB Entry