Back
CVE-2016-6330
CRITICAL
The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-3737.
Published: Sep 27, 2016
Modified: Jun 17, 2026
CWE-502
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (16)
| Vendor | Product | Version |
|---|---|---|
| redhat | jboss_operations_network | 3.0 |
| redhat | jboss_operations_network | 3.0.1 |
| redhat | jboss_operations_network | 3.1 |
| redhat | jboss_operations_network | 3.1.1 |
| redhat | jboss_operations_network | 3.1.2 |
| redhat | jboss_operations_network | 3.1.4 |
| redhat | jboss_operations_network | 3.2.0 |
| redhat | jboss_operations_network | 3.2.1 |
| redhat | jboss_operations_network | 3.2.2 |
| redhat | jboss_operations_network | 3.2.3 |
| redhat | jboss_operations_network | 3.3.1 |
| redhat | jboss_operations_network | 3.3.2 |
| redhat | jboss_operations_network | 3.3.3 |
| redhat | jboss_operations_network | 3.3.4 |
| redhat | jboss_operations_network | 3.3.5 |
| redhat | jboss_operations_network | 3.3.6 |
GitHub Security Advisory GHSA-hpgf-x5r5-6h89
The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured...
References (6)
- http://www.securityfocus.com/bid/92568 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1368864 Issue Tracking, Mitigation, Vendor Advisory
- https://www.tenable.com/security/research/tra-2016-22
- http://www.securityfocus.com/bid/92568 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1368864 Issue Tracking, Mitigation, Vendor Advisory
- https://www.tenable.com/security/research/tra-2016-22
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
10.63%
Top 5% most likely to be exploited
Threat Score
42.4 / 100
Data Sources
NVD
EPSS
GitHub