CVE-2017-12149

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:jboss_enterprise_application_platform:-:*:*:*:text-only:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.1.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.1.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.1.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.2.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.2.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.2.2:*:*:*:*:*:*:*

History

24 Jul 2024, 16:52

Type Values Removed Values Added
CPE cpe:2.3:a:redhat:jboss_enterprise_application_platform:-:*:*:*:text-only:*:*:*
References () http://www.securityfocus.com/bid/100591 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/100591 - Broken Link, Third Party Advisory, VDB Entry
References () https://access.redhat.com/errata/RHSA-2018:1607 - () https://access.redhat.com/errata/RHSA-2018:1607 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2018:1608 - () https://access.redhat.com/errata/RHSA-2018:1608 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=1486220 - Issue Tracking, Vendor Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=1486220 - Issue Tracking
References () https://github.com/gottburgm/Exploits/tree/master/CVE-2017-12149 - () https://github.com/gottburgm/Exploits/tree/master/CVE-2017-12149 - Third Party Advisory

Information

Published : 2017-10-04 21:01

Updated : 2024-07-24 16:52


NVD link : CVE-2017-12149

Mitre link : CVE-2017-12149

CVE.ORG link : CVE-2017-12149


JSON object : View

Products Affected

redhat

  • jboss_enterprise_application_platform
CWE
CWE-502

Deserialization of Untrusted Data