SecurityTracker.com
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 


Category:   Application (Security)  >   McAfee ePolicy Orchestrator Vendors:   McAfee
(McAfee Issues Fix for McAfee ePolicy Orchestrator) Apache Commons Components Deserialization in InvokerTransformer Lets Remote Users Execute Arbitrary Code on the Target System
SecurityTracker Alert ID:  1034631
SecurityTracker URL:  http://securitytracker.com/id/1034631
CVE Reference:   CVE-2015-8765   (Links to External Site)
Date:  Jan 8 2016
Impact:   Execution of arbitrary code via network, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  Exploit Included:  Yes  
Version(s): 4.6.9 and prior, 5.1.3 and prior, 5.3.1 and prior
Description:   A vulnerability was reported in Apache Commons Components. A remote user can execute arbitrary code on the target system. McAfee ePolicy Orchestrator is affected.

A remote user can send specially crafted data to an application or application server that uses or includes the Java 'InvokerTransformer.class' to deserialize data to execute arbitrary code on the target system.

Applications that deserialize untrusted Java objects may be affected.

Applications that use other libraries (e.g., Groovy, Spring) may also be affected.

Application servers (e.g., WebLogic, WebSphere, JBoss) may be affected.

Steve Breen of Foxglove reported details of this vulnerability.

The advisory is available at:

http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/#commons

Christopher Frohoff and Gabriel Lawrence originally reported this vulnerability [at AppSecCali 2015 in January 2015].

The original advisory is available at:

http://www.slideshare.net/frohoff1/appseccali-2015-marshalling-pickles

Impact:   A remote user can execute arbitrary code on the target system.
Solution:   McAfee has issued a fix for McAfee ePolicy Orchestrator.

For 5.1.3: Hotfix ePO5xHF1106041.zip
For 5.3.1: Hotfix ePO5xHF1106041.zip

A fix is pending for version 5.1.4 (Q2 2016)

The McAfee advisory is available at:

https://kc.mcafee.com/corporate/index?page=content&id=SB10144

Cause:   Access control error
Underlying OS:  Windows (Any)

Message History:   This archive entry is a follow-up to the message listed below.
Nov 9 2015 Apache Commons Components Deserialization in InvokerTransformer Lets Remote Users Execute Arbitrary Code on the Target System



 Source Message Contents



[Original Message Not Available for Viewing]


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2019, SecurityGlobal.net LLC