{"id":"CVE-2016-2510","aliases":["GHSA-gxg6-rc6c-v673"],"url":"https://o3.security/vulnerability/CVE-2016-2510","summary":"Improper Input Validation in BeanShell","details":"BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to execute arbitrary code via crafted serialized data, related to XThis.Handler.","published":"2016-04-07T20:59:05.567Z","modified":"2026-07-08T12:43:41.883617Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache-extras.beanshell:bsh","fixedVersion":"2.0b6"}],"fix":{"url":"https://github.com/beanshell/beanshell/commit/1ccc66bb693d4e46a34a904db8eeff07808d2ced","label":"beanshell/beanshell@1ccc66b"},"references":[{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00056.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00078.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-0539.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-0540.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-2035.html"},{"type":"ADVISORY","url":"http://www.debian.org/security/2016/dsa-3504"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/84139"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1035440"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-2923-1"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2016:1135"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2016:1376"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:1545"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201607-17"},{"type":"FIX","url":"https://github.com/beanshell/beanshell/commit/1ccc66bb693d4e46a34a904db8eeff07808d2ced"},{"type":"FIX","url":"https://github.com/beanshell/beanshell/commit/7c68fde2d6fc65e362f20863d868c112a90a9b49"},{"type":"FIX","url":"https://github.com/beanshell/beanshell/releases/tag/2.0b6"},{"type":"EVIDENCE","url":"https://github.com/frohoff/ysoserial/pull/13"},{"type":"EVIDENCE","url":"https://www.rsaconference.com/writable/presentations/file_upload/asd-f03-serial-killer-silently-pwning-your-java-endpoints.pdf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-2510"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:43:41.883617Z"}}