peter bassill · operator
$ cve CVE-2017-12149 JSON

CVE-2017-12149 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 90.7% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-10.

Description

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS90.71% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-502
On CISA KEVyes — remediate by 2022-06-10
Public exploitnone known
Published2017-10-04
Last modified2026-08-13

CISA KEV

NameRed Hat JBoss Application Server Remote Code Execution Vulnerability
Added2021-12-10
Due2022-06-10
Vendor / productRed Hat / JBoss Application Server
Ransomware useknown

Affected (1)

VendorProduct
redhatjboss enterprise application platform

References

→ the Explorer  ·  watch your stack  ·  NVD