An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue will not be fixed.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xml-rpc | Apache | 3.1 (including) | 3.1 (including) |
Xml-rpc | Apache | 3.1.1 (including) | 3.1.1 (including) |
Xml-rpc | Apache | 3.1.2 (including) | 3.1.2 (including) |
Xml-rpc | Apache | 3.1.3 (including) | 3.1.3 (including) |
Red Hat Fuse 7.6.0 | RedHat | camel-xmlrpc | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | rh-java-common-xmlrpc-1:3.1.3-8.17.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-java-common-xmlrpc-1:3.1.3-8.17.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | RedHat | rh-java-common-xmlrpc-1:3.1.3-8.17.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | RedHat | rh-java-common-xmlrpc-1:3.1.3-8.17.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | RedHat | rh-java-common-xmlrpc-1:3.1.3-8.17.el7 | * |
Libxmlrpc3-java | Ubuntu | bionic | * |
Libxmlrpc3-java | Ubuntu | disco | * |
Libxmlrpc3-java | Ubuntu | eoan | * |
Libxmlrpc3-java | Ubuntu | esm-apps/bionic | * |
Libxmlrpc3-java | Ubuntu | esm-apps/xenial | * |
Libxmlrpc3-java | Ubuntu | trusty | * |
Libxmlrpc3-java | Ubuntu | xenial | * |