CVE-2016-2510
bsh - security update
8.1
HIGH
CVSS 3.1
EPSS 70.4%
Description
BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to execute arbitrary code via crafted serialized data, related to XThis.Handler.
How to fix CVE-2016-2510
To remediate CVE-2016-2510, upgrade the affected package to a fixed version below.
- Debian/bsh—upgrade to 2.0b4-16 or later
- —upgrade to 2.0b4-12+deb6u1 or later
- —upgrade to 2.0b4-12+deb7u1 or later
- —upgrade to 2.0b6 or later
Is CVE-2016-2510 being exploited?
Likely — EPSS is 70.4%, placing CVE-2016-2510 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (4)
- from 0, < 2.0b4-16
- from 0, < 2.0b4-12+deb6u1
- from 0, < 2.0b4-12+deb7u1
- from 0, < 2.0b6
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.1 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |