CVE-2016-1487: High severity lexmark markvision enterprise vulnerability
Published Mar 9, 2020
·Updated
Lexmark Markvision Enterprise before 2.3.0 misuses the Apache Commons Collections Library, leading to remote code execution because of Java deserialization.
Affected Software
1 affected component
Lexmark Markvision Enterprise<2.3.0
Event History
Mar 9, 2020
CVE Published
via MITRE·06:06 PM
Data Sourced
via MITRE·06:06 PM
Description
Frequently Asked Questions
1
What is CVE-2016-1487?
CVE-2016-1487 is a vulnerability in Lexmark Markvision Enterprise before 2.3.0 that leads to remote code execution due to misuse of the Apache Commons Collections Library and Java deserialization.
2
What software is affected by CVE-2016-1487?
Lexmark Markvision Enterprise versions up to 2.3.0 are affected by CVE-2016-1487.
3
What is the severity of CVE-2016-1487?
CVE-2016-1487 has a severity rating of 8.8 (high).
4
How does CVE-2016-1487 lead to remote code execution?
CVE-2016-1487 leads to remote code execution due to the misuse of the Apache Commons Collections Library and Java deserialization.
5
How can I fix CVE-2016-1487?
To fix CVE-2016-1487, update Lexmark Markvision Enterprise to version 2.3.0 or higher.