CVE-2016-6809

CRITICAL9.8EPSS 7.0%

Apache Tika allows Java code execution for serialized objects embedded in MATLAB files

Published: 10/17/2018Modified: 4/28/2026

Description

Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (13)