CVE-2016-5983

high

Description

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11, 9.0 before 9.0.0.2, and Liberty before 16.0.0.4 allows remote authenticated users to execute arbitrary Java code via a crafted serialized object.

References

https://www-01.ibm.com/support/docview.wss?uid=swg21990060

https://euvd.enisa.europa.eu/vulnerability/EUVD-2016-6917

http://www.securityfocus.com/bid/93162

http://www-01.ibm.com/support/docview.wss?uid=swg1PI62375

Details

Source: Mitre, NVD

Published: 2016-10-05

Updated: 2026-06-17

Risk Information

CVSS v2

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.04116