An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue will not be fixed.
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "3.1.3-7+deb8u1build0.16.04.1",
"binary_name": "libxmlrpc3-client-java"
},
{
"binary_version": "3.1.3-7+deb8u1build0.16.04.1",
"binary_name": "libxmlrpc3-common-java"
},
{
"binary_version": "3.1.3-7+deb8u1build0.16.04.1",
"binary_name": "libxmlrpc3-server-java"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "3.1.3-9+deb10u1build0.18.04.1",
"binary_name": "libxmlrpc3-client-java"
},
{
"binary_version": "3.1.3-9+deb10u1build0.18.04.1",
"binary_name": "libxmlrpc3-common-java"
},
{
"binary_version": "3.1.3-9+deb10u1build0.18.04.1",
"binary_name": "libxmlrpc3-server-java"
}
]
}