PT-2016-7197 · Red Hat · Red Hat Jboss Enterprise Application Platform
Federico Dotta
+1
·
Published
2016-10-13
·
Updated
2016-12-23
·
CVE-2016-7065
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Red Hat JBoss Enterprise Application Platform (EAP) versions 4 and 5
Description
The issue allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object. This is related to the JMX servlet in the affected software.
Recommendations
For Red Hat JBoss Enterprise Application Platform (EAP) versions 4 and 5, consider restricting access to the JMX servlet as a temporary workaround until a patch is available.
Exploit
Fix
DoS
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Jboss Enterprise Application Platform