CVE-2016-0779: Apache Tomee
Critical severity, CVSS 9.8. EPSS: 9.9% chance of exploitation in the next 30 days.
The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted serialized object.
Affected products
- Apache Tomee: up to and including 1.7.3; version 7.0.0 only
Published 2017-04-11. Last modified 2026-06-17.