vulnerability
Oracle Linux: CVE-2016-7050: ELSA-2016-2604: resteasy-base security and bug fix update (IMPORTANT)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:N/AC:L/Au:N/C:P/I:P/A:P) | Sep 23, 2016 | Nov 9, 2016 | Dec 3, 2025 |
Severity
7
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Sep 23, 2016
Added
Nov 9, 2016
Modified
Dec 3, 2025
Description
SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to execute arbitrary code.
It was discovered that under certain conditions RESTEasy could be forced to parse a request with SerializableProvider, resulting in deserialization of potentially untrusted data. An attacker could possibly use this flaw execute arbitrary code with the permissions of the application using RESTEasy.
It was discovered that under certain conditions RESTEasy could be forced to parse a request with SerializableProvider, resulting in deserialization of potentially untrusted data. An attacker could possibly use this flaw execute arbitrary code with the permissions of the application using RESTEasy.
Solutions
oracle-linux-upgrade-resteasy-baseoracle-linux-upgrade-resteasy-base-atom-provideroracle-linux-upgrade-resteasy-base-clientoracle-linux-upgrade-resteasy-base-jackson-provideroracle-linux-upgrade-resteasy-base-javadocoracle-linux-upgrade-resteasy-base-jaxb-provideroracle-linux-upgrade-resteasy-base-jaxrsoracle-linux-upgrade-resteasy-base-jaxrs-alloracle-linux-upgrade-resteasy-base-jaxrs-apioracle-linux-upgrade-resteasy-base-jettison-provideroracle-linux-upgrade-resteasy-base-providers-pomoracle-linux-upgrade-resteasy-base-resteasy-pomoracle-linux-upgrade-resteasy-base-tjws
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.