Tracker / CVE-2015-3253
CVE-2015-3253
Critical 9.8
The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.
Affected products and versions
| apache | groovy |
|---|---|
| oracle | health_sciences_clinical_development_center |
| oracle | retail_order_broker_cloud_service |
| oracle | retail_service_backbone |
| oracle | retail_store_inventory_management |
| oracle | webcenter_sites |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.