Back

CVE-2016-6330

CRITICAL

The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-3737.

Published: Sep 27, 2016 Modified: Jun 17, 2026
CWE-502

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (16)

Vendor Product Version
redhat jboss_operations_network 3.0
redhat jboss_operations_network 3.0.1
redhat jboss_operations_network 3.1
redhat jboss_operations_network 3.1.1
redhat jboss_operations_network 3.1.2
redhat jboss_operations_network 3.1.4
redhat jboss_operations_network 3.2.0
redhat jboss_operations_network 3.2.1
redhat jboss_operations_network 3.2.2
redhat jboss_operations_network 3.2.3
redhat jboss_operations_network 3.3.1
redhat jboss_operations_network 3.3.2
redhat jboss_operations_network 3.3.3
redhat jboss_operations_network 3.3.4
redhat jboss_operations_network 3.3.5
redhat jboss_operations_network 3.3.6

GitHub Security Advisory GHSA-hpgf-x5r5-6h89

The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 10.63%

Top 5% most likely to be exploited

Threat Score 42.4 / 100

Data Sources

NVD EPSS GitHub