Description
The serialization implementation in JBoss Drools in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 and JBoss Enterprise SOA Platform 4.2 and 4.3 supports the embedding of class files, which allows remote attackers to execute arbitrary code via a crafted static initializer.
Remediation
References
Related Vulnerabilities
WordPress Plugin Mapwiz SQL Injection (1.0.1)
MySQL CVE-2016-5634 Vulnerability (CVE-2016-5634)
WordPress Plugin 3D Product configurator for WooCommerce Arbitrary File Upload (1.5.531)
WordPress Plugin YARPP-Yet Another Related Posts PHP Object Injection (4.4)
WordPress Plugin OnePress Social Locker Multiple Unspecified Vulnerabilities (4.2.5)