vendor:
N/A
by:
Rapid7
7,5
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: N/A
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: CVE-2013-5456
CPE: N/A
Metasploit:
https://www.rapid7.com/db/vulnerabilities/ibm-java-cve-2016-0376/, https://www.rapid7.com/db/vulnerabilities/ibm-aix-cve-2016-0376/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2016-0376/, https://www.rapid7.com/db/vulnerabilities/ibm-aix-cve-2013-5456/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2013-5456/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2013-1507/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
Metasploit3
This module exploits a vulnerability in the JDWP protocol, which is used for debugging Java applications. The vulnerability allows an attacker to send malicious packets to the target, which can be used to execute arbitrary code.
Mitigation:
Disable the JDWP protocol on the target system.