CVE-2017-12149
קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Red Hat JBoss Application Server Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 91% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-502
מוצרים מושפעים
redhat: jboss enterprise application platform
קישורים
- http://www.securityfocus.com/bid/100591 Broken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:1607 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1608 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1486220 Issue Tracking
- https://github.com/gottburgm/Exploits/tree/master/CVE-2017-12149 Third Party Advisory
- http://www.securityfocus.com/bid/100591 Broken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:1607 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1608 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1486220 Issue Tracking
- https://github.com/gottburgm/Exploits/tree/master/CVE-2017-12149 Third Party Advisory