« Volver al listado

CVE-2016-8749

Estado: ModificadaCrítica (9.8)—

Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2016-8749",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@apache.org",
      "affectedData": [
        {
          "vendor": "Apache Software Foundation",
          "product": "Apache Camel",
          "versions": [
            {
              "status": "affected",
              "version": "2.16.0 to 2.16.4"
            },
            {
              "status": "affected",
              "version": "2.17.0 to 2.17.4"
            },
            {
              "status": "affected",
              "version": "2.18.0 to 2.18.1"
            },
            {
              "status": "affected",
              "version": "The unsupported Camel 2.x (2.14 and earlier) versions may be also affected."
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-03-28T18:59:00.143",
  "references": [
    {
      "url": "http://camel.apache.org/security-advisories.data/CVE-2016-8749.txt.asc?version=2&modificationDate=1486565034000&api=v2",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2017/05/22/2",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/97179",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2017:1832",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3E",
      "source": "security@apache.org"
    },
    {
      "url": "https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E",
      "source": "security@apache.org"
    },
    {
      "url": "https://www.github.com/mbechler/marshalsec/blob/master/marshalsec.pdf?raw=true",
      "tags": [
        "Exploit",
        "Technical Description",
        "Third Party Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "http://camel.apache.org/security-advisories.data/CVE-2016-8749.txt.asc?version=2&modificationDate=1486565034000&api=v2",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2017/05/22/2",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/97179",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2017:1832",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3E",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.github.com/mbechler/marshalsec/blob/master/marshalsec.pdf?raw=true",
      "tags": [
        "Exploit",
        "Technical Description",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-502"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks."
    },
    {
      "lang": "es",
      "value": "Apache Camel's Jackson y JacksonXML operación unmarshalling son vulnerables a ataques de ejecución remota de código."
    }
  ],
  "lastModified": "2026-06-17T00:54:57.087",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:camel:2.16.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2823D06C-99B3-4959-9821-CC5A850E11C5"
            },
            {
              "criteria": "cpe:2.3:a:apache:camel:2.16.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CDAFA7CF-DD09-484A-A1E9-89EFB7AF5ED2"
            },
            {
              "criteria": "cpe:2.3:a:apache:camel:2.16.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E7116415-89C0-4D83-8173-E3EBCF71F51F"
            },
            {
              "criteria": "cpe:2.3:a:apache:camel:2.16.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "540EE44D-01AF-4AC2-BC76-DA6917F42DEF"
            },
            {
              "criteria": "cpe:2.3:a:apache:camel:2.16.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C265A5EE-C7E8-48E4-892B-9B87198A8166"
            },
            {
              "criteria": "cpe:2.3:a:apache:camel:2.17.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4057EE83-770C-4448-A020-3ADBA340B01E"
            },
            {
              "criteria": "cpe:2.3:a:apache:camel:2.17.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1CE7AA4A-DCC5-4074-9509-A24FAB558527"
            },
            {
              "criteria": "cpe:2.3:a:apache:camel:2.17.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A8DB9E52-C5B3-469B-8C04-B2DFDF6199D5"
            },
            {
              "criteria": "cpe:2.3:a:apache:camel:2.17.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DD84467E-AAC5-4147-A295-75BA169B1318"
            },
            {
              "criteria": "cpe:2.3:a:apache:camel:2.17.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A427238F-0D26-44AF-90A7-394A14B185FE"
            },
            {
              "criteria": "cpe:2.3:a:apache:camel:2.18.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "706C1A6D-2C4D-4A8F-BB64-4E36954CB0B7"
            },
            {
              "criteria": "cpe:2.3:a:apache:camel:2.18.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AC9C31F3-91A7-4BBF-B5FA-44C2C008A71F"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@apache.org"
}