PT-2017-17777 · Red Hat · Jboss Application Server+1

Adam Mariš

+1

·

Publicado

2017-05-19

·

Atualizado

2023-03-24

·

CVE-2017-7504

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jboss Application Server versions prior to 5.0
Description The issue allows remote attackers to execute arbitrary code via crafted serialized data due to a lack of restriction on the classes for which deserialization is performed in the JMS over HTTP Invocation Layer of the JbossMQ implementation.
Recommendations For Jboss Application Server versions prior to 5.0, consider disabling the JMS over HTTP Invocation Layer to prevent exploitation until a fix is available.

Exploit

Correção

RCE

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-7504

Produtos afetados

Jboss Application Server
Jbossmq