First published: Wed Oct 05 2016(Updated: )
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11, 9.0 before 9.0.0.2, and Liberty before 16.0.0.4 allows remote authenticated users to execute arbitrary Java code via a crafted serialized object.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server | =7.0 | |
IBM WebSphere Application Server | =7.0.0.0 | |
IBM WebSphere Application Server | =7.0.0.1 | |
IBM WebSphere Application Server | =7.0.0.2 | |
IBM WebSphere Application Server | =7.0.0.3 | |
IBM WebSphere Application Server | =7.0.0.4 | |
IBM WebSphere Application Server | =7.0.0.5 | |
IBM WebSphere Application Server | =7.0.0.6 | |
IBM WebSphere Application Server | =7.0.0.7 | |
IBM WebSphere Application Server | =7.0.0.8 | |
IBM WebSphere Application Server | =7.0.0.9 | |
IBM WebSphere Application Server | =7.0.0.10 | |
IBM WebSphere Application Server | =7.0.0.11 | |
IBM WebSphere Application Server | =7.0.0.12 | |
IBM WebSphere Application Server | =7.0.0.13 | |
IBM WebSphere Application Server | =7.0.0.14 | |
IBM WebSphere Application Server | =7.0.0.15 | |
IBM WebSphere Application Server | =7.0.0.16 | |
IBM WebSphere Application Server | =7.0.0.17 | |
IBM WebSphere Application Server | =7.0.0.18 | |
IBM WebSphere Application Server | =7.0.0.19 | |
IBM WebSphere Application Server | =7.0.0.21 | |
IBM WebSphere Application Server | =7.0.0.22 | |
IBM WebSphere Application Server | =7.0.0.23 | |
IBM WebSphere Application Server | =7.0.0.24 | |
IBM WebSphere Application Server | =7.0.0.25 | |
IBM WebSphere Application Server | =7.0.0.27 | |
IBM WebSphere Application Server | =7.0.0.28 | |
IBM WebSphere Application Server | =7.0.0.29 | |
IBM WebSphere Application Server | =7.0.0.31 | |
IBM WebSphere Application Server | =7.0.0.32 | |
IBM WebSphere Application Server | =7.0.0.33 | |
IBM WebSphere Application Server | =7.0.0.34 | |
IBM WebSphere Application Server | =7.0.0.35 | |
IBM WebSphere Application Server | =7.0.0.36 | |
IBM WebSphere Application Server | =7.0.0.37 | |
IBM WebSphere Application Server | =7.0.0.38 | |
IBM WebSphere Application Server | =7.0.0.39 | |
IBM WebSphere Application Server | =7.0.0.41 | |
IBM WebSphere Application Server | =8.0 | |
IBM WebSphere Application Server | =8.0.0.0 | |
IBM WebSphere Application Server | =8.0.0.1 | |
IBM WebSphere Application Server | =8.0.0.2 | |
IBM WebSphere Application Server | =8.0.0.3 | |
IBM WebSphere Application Server | =8.0.0.4 | |
IBM WebSphere Application Server | =8.0.0.5 | |
IBM WebSphere Application Server | =8.0.0.6 | |
IBM WebSphere Application Server | =8.0.0.7 | |
IBM WebSphere Application Server | =8.0.0.8 | |
IBM WebSphere Application Server | =8.0.0.9 | |
IBM WebSphere Application Server | =8.0.0.10 | |
IBM WebSphere Application Server | =8.0.0.11 | |
IBM WebSphere Application Server | =8.0.0.12 | |
IBM WebSphere Application Server | =8.5.0.0 | |
IBM WebSphere Application Server | =8.5.0.0 | |
IBM WebSphere Application Server | =8.5.0.1 | |
IBM WebSphere Application Server | =8.5.0.2 | |
IBM WebSphere Application Server | =8.5.5.0 | |
IBM WebSphere Application Server | =8.5.5.1 | |
IBM WebSphere Application Server | =8.5.5.2 | |
IBM WebSphere Application Server | =8.5.5.4 | |
IBM WebSphere Application Server | =8.5.5.5 | |
IBM WebSphere Application Server | =8.5.5.6 | |
IBM WebSphere Application Server | =8.5.5.7 | |
IBM WebSphere Application Server | =8.5.5.8 | |
IBM WebSphere Application Server | =8.5.5.9 | |
IBM WebSphere Application Server | =9.0.0.0 | |
IBM WebSphere Application Server | =8.5.5.10 | |
IBM WebSphere Application Server | =9.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The affected versions include IBM WebSphere Application Server 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11, 9.0 before 9.0.0.2, and Liberty before 16.0.0.4.
CVE-2016-5983 is a remote code execution vulnerability that allows authenticated users to execute arbitrary Java code via a crafted serialized object.
To mitigate CVE-2016-5983, upgrade to the fixed versions of IBM WebSphere Application Server or apply the patches identified by IBM.
The potential impact of CVE-2016-5983 includes unauthorized execution of arbitrary Java code, which can lead to system compromise.
Yes, an attacker needs valid authentication credentials to exploit CVE-2016-5983 and execute arbitrary code.