CVE-2017-7504
HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Server <= Jboss 4.X does not restrict the classes for which it performs deserialization, which allows…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 41.0%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Server <= Jboss 4.X does not restrict the classes for which it performs deserialization, which allows remote attackers to execute arbitrary code via crafted serialized data.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 41.02% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- redhat/jboss enterprise application platform
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/98595Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1451441Issue Tracking
- http://www.securityfocus.com/bid/98595Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1451441Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.