Description
The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serialized Java object in an <ex:serializable> element.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4gqp-296r-j5mq | Apache XML-RPC vulnerable to Deserialization of Untrusted Data |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-02-13T16:27:15.179Z
Reserved: 2016-05-24T00:00:00.000Z
Link: CVE-2016-5003
No data.
Status : Modified
Published: 2017-10-27T18:29:00.260
Modified: 2026-05-13T00:24:29.033
Link: CVE-2016-5003
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA