PT-2017-17777 · Red Hat · Jboss Application Server+1

Adam Mariš

+1

·

Published

2017-05-19

·

Updated

2023-03-24

·

CVE-2017-7504

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jboss Application Server versions prior to 5.0
Description The issue allows remote attackers to execute arbitrary code via crafted serialized data due to a lack of restriction on the classes for which deserialization is performed in the JMS over HTTP Invocation Layer of the JbossMQ implementation.
Recommendations For Jboss Application Server versions prior to 5.0, consider disabling the JMS over HTTP Invocation Layer to prevent exploitation until a fix is available.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2017-7504

Affected Products

Jboss Application Server
Jbossmq