CVE-2016-3737: Red Hat JBoss Operations Network

Critical severity, CVSS 9.8. EPSS: 6.8% chance of exploitation in the next 30 days.

The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization.

Affected products

  • Red Hat JBoss Operations Network: up to and including 3.3.5

Published 2016-08-02. Last modified 2026-06-17.