An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue will not be fixed.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade xmlrpc-javadocUpgrade xmlrpc-commonUpgrade xmlrpc-serverUpgrade xmlrpc-client | Jun 8, 2023 | Jan 23, 2020 |
| Debian | — | Upgrade libxmlrpc3-java | Feb 3, 2020 | Jan 23, 2020 |
| Gentoo Linux | — | Upgrade dev-java/xmlrpc. | Jan 23, 2024 | Jan 23, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 23, 2020 |
| Ubuntu | — | Upgrade libxmlrpc3-common-javaUpgrade libxmlrpc3-server-javaUpgrade libxmlrpc3-client-java | Sep 16, 2020 | Jan 23, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub