CVE-2016-3737 is a critical vulnerability affecting Red Hat JBoss Operations Network (JON) versions prior to 3.3.6. It allows remote attackers to execute arbitrary code through specially crafted HTTP requests, leveraging a message deserialization flaw. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network without authentication and can lead to complete compromise of confidentiality, integrity, and availability. While there are no known public exploits or active exploitation listed, the vulnerability has garnered significant community discussion, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.3.5CPE matchmatch criteria | cpe:2.3:a:redhat:jboss_operations_network:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R2] Red Hat JBoss Operations Network /jboss-remoting-servlet-invoker/ServerInvokerServlet Jython Deserialization Remote Code Execution
Jul 20, 2016[R2] Red Hat JBoss Operations Network /jboss-remoting-servlet-invoker/ServerInvokerServlet Jython Deserialization Remote Code Execution
Jul 20, 2016[R2] Red Hat JBoss Operations Network /jboss-remoting-servlet-invoker/ServerInvokerServlet Jython Deserialization Remote Code Execution
Jul 20, 2016[R2] Red Hat JBoss Operations Network /jboss-remoting-servlet-invoker/ServerInvokerServlet Jython Deserialization Remote Code Execution
Jul 20, 2016JON: The agent/server communication deserializes data, and does not require authentication
May 6, 2016