REDHAT-BUG-1508123: High severity Apache XML-RPC vulnerability
The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serialized Java object in an <ex:serializable> element.
References:
http://www.openwall.com/lists/oss-security/2016/07/12/5 https://0ang3el.blogspot.in/2016/07/beware-of-ws-xmlrpc-library-in-your.html
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Apache XML-RPC (ws-xmlrpc) 3.1.3from your environment.Remove or replace the vulnerable Apache XML-RPC (ws-xmlrpc) 3.1.3 library from affected deployments (for example, Apache Archiva) until a fixed release is available.
- Remove
Remove
Apache Archivafrom your environment.If Apache Archiva includes or bundles the Apache XML-RPC (ws-xmlrpc) 3.1.3 library, remove or replace the bundled library or disable Archiva's XML-RPC functionality until a vendor-supplied fix is available.
- Remove
Remove
PHP XML-RPCfrom your environment.Uninstall or disable the PHP XML-RPC component/extension if present and not required, until a patched version is available.
- Compensating control
Restrict or block access to XML-RPC endpoints (e.g., via firewall, WAF, or network ACLs) to trusted hosts only to mitigate remote exploitation until affected components are fixed or removed.
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1508123?
The severity of REDHAT-BUG-1508123 is critical due to the potential for remote code execution.
How do I fix REDHAT-BUG-1508123?
To fix REDHAT-BUG-1508123, update the Apache XML-RPC library to the latest version that addresses this vulnerability.
Who is affected by REDHAT-BUG-1508123?
Users of Apache XML-RPC and Apache Archiva are potentially affected by REDHAT-BUG-1508123.
What type of attack does REDHAT-BUG-1508123 enable?
REDHAT-BUG-1508123 enables remote attackers to execute arbitrary code using crafted serialized Java objects.
What component is vulnerable in REDHAT-BUG-1508123?
The vulnerable component in REDHAT-BUG-1508123 is the Apache XML-RPC library version 3.1.3.