Vulnerability Intelligence Report
CVE-2017-7504
HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Server <= Jboss 4.X does not restrict the classes for which it performs deserialization, which allows remote attackers to execute arbitrary code via crafted serialized data.
Nuclei Template
CVSS Base Score
9.8
CRITICAL
EPSS Probability:29.32%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-502 ↗CWE-502
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Red Hat, Inc. | JBoss | 4.x (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2017-04-05T00:00:00 |
| Published | 2017-05-19T20:00:00 |
| Patch Date | 2017-05-18 |
| Last Updated | 2024-08-05T16:04:11 |
Community Chatter & Buzz