Back to search
CVE-2016-5003
Published: Oct 27, 2017
Modified: Feb 13, 2025
PUBLISHED
Description
The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serialized Java object in an <ex:serializable> element.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20160712 Vulnerabilities in Apache Archiva
mailing-list
x_refsource_MLIST
RHSA-2018:1779
vendor-advisory
x_refsource_REDHAT
RHSA-2018:1784
vendor-advisory
x_refsource_REDHAT
91738
vdb-entry
x_refsource_BID
RHSA-2018:2317
vendor-advisory
x_refsource_REDHAT
1036294
vdb-entry
x_refsource_SECTRACK
RHSA-2018:1780
vendor-advisory
x_refsource_REDHAT
apache-archiva-cve20165003-code-exec(115043)
vdb-entry
x_refsource_XF
91736
vdb-entry
x_refsource_BID
RHSA-2018:3768
vendor-advisory
x_refsource_REDHAT
[oss-security] 20200116 [CVE-2019-17570] xmlrpc-common untrusted deserialization
mailing-list
x_refsource_MLIST
[oss-security] 20200124 RE: [CVE-2019-17570] xmlrpc-common untrusted deserialization
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now