Impact
The vulnerability arises from Apache Roller’s XML‑RPC endpoint deserializing vendor extension types without authenticating the requester. Because the servlet processes requests even when the global XML‑RPC feature is disabled, any remote entity can supply malicious XML payloads that trigger deserialization of attacker‑controlled bytes. This flaw can lead to arbitrary code execution on the host running the Roller instance.
Affected Systems
The affected product is Apache Roller version 6.1.5. Users running this version—or any sub‑release that has not yet been updated to 6.1.6 or later—are at risk. No special configuration is required for the vulnerability to be exploitable; the default deployment already exposes the vulnerable endpoint.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. The EPSS score is currently unavailable, but vulnerability disclosure and historical activity suggest that exploitation is possible. The vulnerability is not listed in CISA KEV yet. The likely attack vector is an unauthenticated remote request to the XML‑RPC endpoint. An attacker can send crafted XML data that the server will deserialize before any authentication check, potentially executing arbitrary code on the server.
OpenCVE Enrichment