Jboss EAP Deserialization of Untrusted Data Vulnerability - CVE-2016-3690 - Vulnerability Database

Jboss EAP Deserialization of Untrusted Data Vulnerability - CVE-2016-3690

Critical
Reference: CVE-2016-3690
Title: Jboss EAP Deserialization of Untrusted Data Vulnerability
Overview:

The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.