CVE-2016-7050: Critical severity redhat Enterprise Linux Desktop vulnerability
SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to execute arbitrary code.
Other sources
Under certain conditions it's possible for an attacker to force the use of a SerializableProvider to parse a request in RESTEasy. An attacker can use this flaw to lauch a remote code execution attack.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7050?
CVE-2016-7050 is considered a critical vulnerability as it allows remote attackers to execute arbitrary code.
How do I fix CVE-2016-7050?
To fix CVE-2016-7050, update to the latest patched version of the software affected.
Which software is affected by CVE-2016-7050?
CVE-2016-7050 affects Red Hat Enterprise Linux Desktop 7, HPC Node 7, Server 7, and Workstation 7 versions 7.0.
What vulnerabilities does CVE-2016-7050 exploit?
CVE-2016-7050 exploits the SerializableProvider in RESTEasy, allowing remote code execution under certain conditions.
Is CVE-2016-7050 still a threat?
If you are using the affected versions of Red Hat Enterprise Linux 7 without applying the necessary updates, CVE-2016-7050 remains a significant threat.