HackerFeeds
All CVEs

CVE-2017-12149

CRITICAL9.8
CISA KEV

Published 2017-10-04 · Updated 2026-08-13 · Source secalert@redhat.com

Description

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CWE-502CWE-502CWE-502

CISA Known-Exploited Vulnerability

Product: Red HatJBoss Application Server

Name: Red Hat JBoss Application Server Remote Code Execution Vulnerability

Date added: 2021-12-10 · Due: 2022-06-10

USED IN RANSOMWARE

Required action: Apply updates per vendor instructions.

View on NVD