Java Code Execution Vulnerability in Apache Tika Affects Multiple Versions
CVE-2016-6809

9.8CRITICAL

Key Information:

Vendor
Apache
Status
Vendor
CVE Published:
6 April 2017

Summary

Apache Tika before version 1.14 contains a vulnerability that permits the execution of arbitrary Java code through the native deserialization of serialized objects embedded in MATLAB files. This issue arises from Tika's use of JMatIO, which does not properly handle the security of deserialized objects. As a result, malicious payloads within these files can be executed, potentially leading to significant security breaches within applications utilizing Tika.

References

EPSS Score

9% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.