Vulnerability Intelligence Report
Red Hat JBoss Application Server Remote Code Execution Vulnerability
CVE-2017-12149
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.
CISA KEV
Nuclei Template
SSVC: Active Exploitation
Automatable
Deserialization
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:90.71%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-502 ↗CWE-502
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Red Hat, Inc. | jbossas | n/a (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
90.713%
GitHub Advisory
Vulnerability Class
Deserialization
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2017-08-01T00:00:00 |
| Published | 2017-10-04T20:00:00 |
| Patch Date | 2017-08-29 |
| Last Updated | 2026-08-13T03:55:40 |
Community Chatter & Buzz