Rapid7

vulnerability

Oracle Linux: CVE-2016-7050: ELSA-2016-2604: resteasy-base security and bug fix update (IMPORTANT)

Severity
7
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Sep 23, 2016
Added
Nov 9, 2016
Modified
Dec 3, 2025

Description

SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to execute arbitrary code.
It was discovered that under certain conditions RESTEasy could be forced to parse a request with SerializableProvider, resulting in deserialization of potentially untrusted data. An attacker could possibly use this flaw execute arbitrary code with the permissions of the application using RESTEasy.

Solutions

oracle-linux-upgrade-resteasy-baseoracle-linux-upgrade-resteasy-base-atom-provideroracle-linux-upgrade-resteasy-base-clientoracle-linux-upgrade-resteasy-base-jackson-provideroracle-linux-upgrade-resteasy-base-javadocoracle-linux-upgrade-resteasy-base-jaxb-provideroracle-linux-upgrade-resteasy-base-jaxrsoracle-linux-upgrade-resteasy-base-jaxrs-alloracle-linux-upgrade-resteasy-base-jaxrs-apioracle-linux-upgrade-resteasy-base-jettison-provideroracle-linux-upgrade-resteasy-base-providers-pomoracle-linux-upgrade-resteasy-base-resteasy-pomoracle-linux-upgrade-resteasy-base-tjws
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.