computer vulnerability alert CVE-2016-5983

IBM WebSphere Application Server: code execution via serialized objects

Synthesis of the vulnerability

An attacker can use a vulnerability via serial of IBM WebSphere Application Server, in order to run code.
Impacted software: Security Directory Server, Tivoli Directory Server, Tivoli System Automation, Tivoli Workload Scheduler, WebSphere AS Traditional.
Severity of this computer vulnerability: 3/4.
Consequences of a hack: administrator access/rights, privileged access/rights, user access/rights.
Attacker's origin: internet client.
Creation date: 23/09/2016.
CVE-2016-5983, VIGILANCE-VUL-20686.

Description of the vulnerability

The IBM WebSphere Application Server runs on a Java virtual machine.

It can load serialized objects from external sources. However, it likely does not restrict which classes are loaded when an object is unserialized.

An attacker can therefore send serialized objects to IBM WebSphere Application Server, in order to run code.
