An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue will not be fixed.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Xml-rpc | Apache | 3.1 (including) | 3.1 (including) |
| Xml-rpc | Apache | 3.1.1 (including) | 3.1.1 (including) |
| Xml-rpc | Apache | 3.1.2 (including) | 3.1.2 (including) |
| Xml-rpc | Apache | 3.1.3 (including) | 3.1.3 (including) |
| Red Hat Fuse 7.6.0 | RedHat | camel-xmlrpc | * |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | rh-java-common-xmlrpc-1:3.1.3-8.17.el6 | * |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-java-common-xmlrpc-1:3.1.3-8.17.el7 | * |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | RedHat | rh-java-common-xmlrpc-1:3.1.3-8.17.el7 | * |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | RedHat | rh-java-common-xmlrpc-1:3.1.3-8.17.el7 | * |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | RedHat | rh-java-common-xmlrpc-1:3.1.3-8.17.el7 | * |
| Libxmlrpc3-java | Ubuntu | bionic | * |
| Libxmlrpc3-java | Ubuntu | disco | * |
| Libxmlrpc3-java | Ubuntu | eoan | * |
| Libxmlrpc3-java | Ubuntu | esm-apps/bionic | * |
| Libxmlrpc3-java | Ubuntu | esm-apps/xenial | * |
| Libxmlrpc3-java | Ubuntu | trusty | * |
| Libxmlrpc3-java | Ubuntu | xenial | * |