{"id":"CVE-2016-2173","description":"org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code.","cvssScore":9.8,"cvssVersion":"3.1","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvssMetrics":[{"version":"3.1","score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"},{"version":"2.0","score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"cwes":["CWE-20"],"resolved":"MITIGATED-BY-RASP","published":"2017-04-21","lastModified":"2026-06-17","affectedProducts":[{"vendor":"fedoraproject","product":"fedora","version":"22"},{"vendor":"fedoraproject","product":"fedora","version":"23"},{"vendor":"fedoraproject","product":"fedora","version":"24"},{"vendor":"vmware","product":"spring advanced message queuing protocol","versionEnd":"\u003c1.5.5"}],"totalAffectedProducts":2,"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1326205","source":"patch-hint","tags":["bugzilla"]},{"url":"https://pivotal.io/security/cve-2016-2173","source":"osv","tags":["WEB"]},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2016-April/182551.html","source":"osv","tags":["WEB"]},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2016-April/182850.html","source":"osv","tags":["WEB"]},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2016-April/182959.html","source":"osv","tags":["WEB"]}],"reasoning":{"decidingSource":"secure-rule-match","decidingReason":"Promoted to MITIGATED-BY-RASP (security rule): this CVE's description identifies a deserialization vulnerability that can be mitigated by an ARMR deserialization security rule at the JVM level, without requiring a CVE-specific patch. Matched by description (no specific CWE was assigned by NVD).","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"no-match"},{"rule":"non-java-upstream","stage":"scope","outcome":"no-match"},{"rule":"oracle-component","stage":"scope","outcome":"no-match"},{"rule":"osv-maven","stage":"scope","outcome":"matched","status":"QUEUED-FOR-REVIEW","detail":"Maven packages: org.springframework.amqp:spring-amqp"},{"rule":"patch-hint","stage":"disposition","outcome":"matched","status":"MITIGATION-CANDIDATE","detail":"References include candidate fix URL (bugzilla tier): https://bugzilla.redhat.com/show_bug.cgi?id=1326205"},{"rule":"open-source-maven","stage":"disposition","outcome":"skipped"},{"rule":"poc-derivable","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit","stage":"disposition","outcome":"skipped"},{"rule":"secure-rule-match","stage":"disposition","outcome":"matched","status":"MITIGATED-BY-RASP","detail":"Description mentions \"deserialization\" — mitigable by an ARMR deserialization security rule (CWE not assigned).","decisive":true},{"rule":"below-action-threshold","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit-published","stage":"disposition","outcome":"skipped"}],"patchHintUrl":"https://bugzilla.redhat.com/show_bug.cgi?id=1326205","patchHintTier":"bugzilla","affectedProducts":[{"vendor":"fedoraproject","product":"fedora","isKnown":false,"cpe":"cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*"},{"vendor":"vmware","product":"spring_advanced_message_queuing_protocol","isKnown":false,"cpe":"cpe:2.3:a:vmware:spring_advanced_message_queuing_protocol:*:*:*:*:*:*:*:*"}],"affectedPackages":[{"name":"org.springframework.amqp:spring-amqp","introduced":"0","fixed":"1.5.5"}]},"assessment":{"record":{"state":"active"},"protection":{"level":"full","mechanisms":["security-rule"]},"action":{"state":"available","type":"security-rule"},"review":{"state":"automated","basis":"inferred"}},"exploits":[{"source":"github-poc","url":"https://github.com/HaToan/CVE-2016-2173","title":"HaToan/CVE-2016-2173","date":"2017-03-29T01:25:40Z","stars":4}],"signals":{"hasPOC":true,"pocCount":1,"pocSources":["github-poc"],"topStars":4,"firstPOCDate":"2017-03-29T01:25:40Z"},"kev":{"inKEV":false},"epss":{"available":true,"score":0.06283,"percentile":0.93189},"ssvc":{"available":false},"patchHintUrl":"https://bugzilla.redhat.com/show_bug.cgi?id=1326205","patchHintTier":"bugzilla"}