Vulnerability Description
BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to execute arbitrary code via crafted serialized data, related to XThis.Handler.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Beanshell | Beanshell | 1.0 |
| Debian | Debian Linux | 7.0 |
| Canonical | Ubuntu Linux | 12.04 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00056.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00078.htmlMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0539.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0540.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2035.htmlThird Party Advisory
- http://www.debian.org/security/2016/dsa-3504Third Party Advisory
- http://www.securityfocus.com/bid/84139Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1035440Third Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-2923-1Third Party Advisory
- https://access.redhat.com/errata/RHSA-2016:1135Third Party Advisory
- https://access.redhat.com/errata/RHSA-2016:1376Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1545Third Party Advisory
- https://github.com/beanshell/beanshell/commit/1ccc66bb693d4e46a34a904db8eeff0780PatchThird Party Advisory
- https://github.com/beanshell/beanshell/commit/7c68fde2d6fc65e362f20863d868c112a9PatchThird Party Advisory
- https://github.com/beanshell/beanshell/releases/tag/2.0b6PatchThird Party Advisory
FAQ
What is CVE-2016-2510?
CVE-2016-2510 is a vulnerability with a CVSS score of 8.1 (HIGH). BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to execute arbitrary code via crafted serialized data, r...
How severe is CVE-2016-2510?
CVE-2016-2510 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-2510?
Check the references section above for vendor advisories and patch information. Affected products include: Beanshell Beanshell, Debian Debian Linux, Canonical Ubuntu Linux.