Skip to main content

Vendor/product archive

apache / ws-xmlrpc CVEs

Beta · best-effort

2 CVEs tagged to apache / ws-xmlrpc1 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2016-5003

Published Oct 27, 2017

The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serialized Java object in an <ex:seria…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-5004

Published Jun 6, 2017

The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource consumption) by decompressing…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1