[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2015-3253Date: (C)2015-08-13   (M)2023-12-22


The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 9.8CVSS Score : 7.5
Exploit Score: 3.9Exploit Score: 10.0
Impact Score: 5.9Impact Score: 6.4
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: HIGHAvailability: PARTIAL
Integrity: HIGH 
Availability: HIGH 
  
Reference:
SECTRACK-1034815
http://www.securityfocus.com/archive/1/536012/100/0/threaded
BID-75919
BID-91787
GLSA-201610-01
N/A
RHSA-2016:0066
RHSA-2016:1376
RHSA-2017:2486
RHSA-2017:2596
https://lists.apache.org/thread.html/rbb8e16cc5acab183124572b655bdf5fe1d5b5f477dc267352426c7ed%40%3Cnotifications.shardingsphere.apache.org%3E
http://groovy-lang.org/security.html
http://packetstormsecurity.com/files/132714/Apache-Groovy-2.4.3-Code-Execution.html
http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
http://www.zerodayinitiative.com/advisories/ZDI-15-365/
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324755
https://security.netapp.com/advisory/ntap-20160623-0001/
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html

CPE    105
cpe:/a:apache:groovy:2.1.0
cpe:/a:apache:groovy:2.1.1
cpe:/a:apache:groovy:2.1.2
cpe:/a:apache:groovy:2.1.3
...
CWE    1
CWE-74
OVAL    4
oval:org.secpod.oval:def:504918
oval:org.secpod.oval:def:204590
oval:org.secpod.oval:def:113109
oval:org.secpod.oval:def:109545
...

© SecPod Technologies