CVE-2016-2397

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
17/02/2016
Last modified:
12/04/2025

Description

The cliserver implementation in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote attackers to deserialize and execute arbitrary Java code via crafted XML data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:sonicwall:uma_em5000_firmware:7.2:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:uma_em5000_firmware:8.0:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:uma_em5000_firmware:8.1:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:uma_em5000:-:*:*:*:*:*:*:*
cpe:2.3:a:sonicwall:analyzer:7.2:*:*:*:*:*:*:*
cpe:2.3:a:sonicwall:analyzer:8.0:*:*:*:*:*:*:*
cpe:2.3:a:sonicwall:analyzer:8.1:*:*:*:*:*:*:*
cpe:2.3:a:sonicwall:global_management_system:7.2:*:*:*:*:*:*:*
cpe:2.3:a:sonicwall:global_management_system:8.0:*:*:*:*:*:*:*
cpe:2.3:a:sonicwall:global_management_system:8.1:*:*:*:*:*:*:*