The RMI service in SolarWinds Virtualization Manager 6.3.1 and earlier allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
References
Configurations
History
21 Nov 2024, 02:50
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/137486/Solarwinds-Virtualization-Manager-6.3.1-Java-Deserialization.html - Exploit | |
References | () http://seclists.org/fulldisclosure/2016/Jun/25 - | |
References | () http://seclists.org/fulldisclosure/2016/Jun/29 - |
Information
Published : 2016-06-17 15:59
Updated : 2024-11-21 02:50
NVD link : CVE-2016-3642
Mitre link : CVE-2016-3642
CVE.ORG link : CVE-2016-3642
JSON object : View
Products Affected
solarwinds
- virtualization_manager
CWE