CVE-2016-6809

Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:nutch:2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:tika:*:*:*:*:*:*:*:*

Information

Published : 2017-04-06 21:59

Updated : 2020-08-19 19:17


NVD link : CVE-2016-6809

Mitre link : CVE-2016-6809


JSON object : View

Products Affected

apache

  • nutch
  • tika
CWE
CWE-502

Deserialization of Untrusted Data