CVE-2017-12149
CVE Published | 2017-10-04 |
---|---|
Related CWE(s) | CWE-502: Deserialization of Untrusted Data |
Related Vendor(s) | redhat |
Related Product(s) | jboss_enterprise_application_platform |
Exploitation Reported (CISA KEV) | 2021-12-10 |
CVSS 3 Base Score | 9.8 (CRITICAL) |
CVSS 3 Attack Complexity | LOW |
CVSS 3 Attack Vector | NETWORK |
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph