The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL loading of Java MBeans, which allows remote attackers to execute arbitrary Java code by registering MBeans.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published: 2016-09-29T10:00:00

Updated: 2024-08-06T00:46:40.256Z

Reserved: 2016-05-26T00:00:00

Link: CVE-2016-5062

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2016-09-29T10:59:01.737

Modified: 2017-04-10T01:59:00.363

Link: CVE-2016-5062

cve-icon Redhat

No data.