Vulnerability Name:

CVE-2016-4000 (CCN-129438)

Assigned:2016-01-19
Published:2016-01-19
Updated:2020-07-15
Summary:Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.
CVSS v3 Severity:9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
9.8 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-502
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: Jython Web site
Issue2454

Source: CONFIRM
Type: Vendor Advisory
http://bugs.jython.org/issue2454

Source: MITRE
Type: CNA
CVE-2016-4000

Source: DEBIAN
Type: Third Party Advisory
DSA-3893

Source: CCN
Type: Oracle CPUApr2019
Oracle Critical Patch Update Advisory - April 2019

Source: CCN
Type: Oracle CPUJan2019
Oracle Critical Patch Update Advisory - January 2019

Source: CCN
Type: Oracle CPUOct2018
Oracle Critical Patch Update Advisory - October 2018

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html

Source: CCN
Type: Oracle CPUOct2019
Oracle Critical Patch Update Advisory - October 2019

Source: BID
Type: UNKNOWN
105647

Source: CCN
Type: BID-105647
Oracle Enterprise Manager Ops Center CVE-2016-4000 Remote Security Vulnerability

Source: CONFIRM
Type: Mailing List, Third Party Advisory
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=864859

Source: XF
Type: UNKNOWN
jython-cve20164000-code-exec(129438)

Source: CONFIRM
Type: Third Party Advisory
https://hg.python.org/jython/file/v2.7.1rc1/NEWS

Source: CCN
Type: Python Web site
Do not deserialize PyFunction objects. Fixes #2454

Source: CONFIRM
Type: Patch, Third Party Advisory
https://hg.python.org/jython/rev/d06e29d100c0

Source: MLIST
Type: UNKNOWN
[infra-devnull] 20190402 [GitHub] [flink] aloyszhang opened pull request #8100: [FLINK-12082] Bump up the jython-standalone version

Source: MISC
Type: Third Party Advisory
https://security-tracker.debian.org/tracker/CVE-2016-4000

Source: GENTOO
Type: UNKNOWN
GLSA-201710-28

Source: MISC
Type: Third Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGPYTHON-31451

Source: CCN
Type: Oracle CPUApr2020
Oracle Critical Patch Update Advisory - April 2020

Source: N/A
Type: UNKNOWN
N/A

Source: CCN
Type: Oracle CPUJan2020
Oracle Critical Patch Update Advisory - January 2020

Source: MISC
Type: UNKNOWN
https://www.oracle.com/security-alerts/cpujan2020.html

Source: CCN
Type: Oracle CPUJul2020
Oracle Critical Patch Update Advisory - July 2020

Source: MISC
Type: UNKNOWN
https://www.oracle.com/security-alerts/cpujul2020.html

Source: MISC
Type: UNKNOWN
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html

Source: CONFIRM
Type: UNKNOWN
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html

Source: MISC
Type: UNKNOWN
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html

Vulnerable Configuration:Configuration 1:
  • cpe:/a:jython_project:jython:2.7.0:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:debian:debian_linux:8.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:oracle:enterprise_manager:12.1.0.5:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:application_testing_suite:12.5.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:enterprise_manager:13.2:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:enterprise_manager_ops_center:12.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:application_testing_suite:13.1.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:application_testing_suite:13.2.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:banking_platform:2.6:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:enterprise_manager_ops_center:12.3.3:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:communications_diameter_signaling_router:8:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:utilities_network_management_system:2.3:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:banking_platform:2.6.1:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:banking_platform:2.6.2:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:utilities_network_management_system:1.12.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:utilities_network_management_system:2.3.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:utilities_network_management_system:2.3.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:communications_diameter_signaling_router:8.1:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:communications_diameter_signaling_router:8.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:com.ubuntu.trusty:def:20164000000
    V
    CVE-2016-4000 on Ubuntu 14.04 LTS (trusty) - medium.
    2017-07-06
    oval:com.ubuntu.xenial:def:20164000000
    V
    CVE-2016-4000 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-07-06
    oval:com.ubuntu.xenial:def:201640000000000
    V
    CVE-2016-4000 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-07-06
    BACK
    jython_project jython 2.7.0
    debian debian linux 8.0
    oracle enterprise manager 12.1.0.5
    oracle application testing suite 12.5.0.3
    oracle enterprise manager 13.2
    oracle enterprise manager ops center 12.2.2
    oracle application testing suite 13.1.0.1
    oracle application testing suite 13.2.0.1
    oracle banking platform 2.6
    oracle enterprise manager ops center 12.3.3
    oracle communications diameter signaling router 8
    oracle utilities network management system 2.3
    oracle banking platform 2.6.1
    oracle banking platform 2.6.2
    oracle utilities network management system 1.12.0.3
    oracle utilities network management system 2.3.0.1
    oracle utilities network management system 2.3.0.2
    oracle application testing suite 13.3.0.1
    oracle communications diameter signaling router 8.1
    oracle communications diameter signaling router 8.2