EUVD-2017-3733
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 10 Dec 2021. Evidence sources: cisa_kev, eukev_kev.
- ENISA score
- 9.8 · CVSS 3.1
- Advisory evidence
- 2 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_redhat · RHSA-2018:1607Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 5.2 security update
- csaf_redhat · RHSA-2018:1608Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 5.2 security update
