ZeroHour

CVE-2016-2510

PoC ×2
CVSS 3.1
8.1 high
EPSS
70%p99
Published
()
Modified
Description

BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to execute arbitrary code via crafted serialized data, related to XThis.Handler.

Vendors
beanshelldebiancanonical
Products
beanshell, debian linux, ubuntu linux
Weakness
CWE-19
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.