Remote Code Execution Vulnerability in Lexmark Markvision Enterprise
CVE-2016-1487

8.8HIGH

Key Information:

Vendor

Lexmark

Vendor
CVE Published:
9 March 2020

What is CVE-2016-1487?

A vulnerability in Lexmark's Markvision Enterprise prior to version 2.3.0 has been identified, stemming from the misuse of the Apache Commons Collections Library. This critical flaw allows attackers to exploit Java deserialization issues, potentially enabling them to execute arbitrary code on affected systems. Organizations utilizing earlier versions of this product are advised to upgrade promptly to mitigate the risk of unauthorized access and control.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.