CVE-2017-12149 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 90.7% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-06-10.
Description
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 90.71% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-502 |
| On CISA KEV | yes — remediate by 2022-06-10 |
| Public exploit | none known |
| Published | 2017-10-04 |
| Last modified | 2026-08-13 |
CISA KEV
| Name | Red Hat JBoss Application Server Remote Code Execution Vulnerability |
|---|---|
| Added | 2021-12-10 |
| Due | 2022-06-10 |
| Vendor / product | Red Hat / JBoss Application Server |
| Ransomware use | known |
Affected (1)
| Vendor | Product |
|---|---|
| redhat | jboss enterprise application platform |
References
- http://www.securityfocus.com/bid/100591
- https://access.redhat.com/errata/RHSA-2018:1607
- https://access.redhat.com/errata/RHSA-2018:1608
- https://bugzilla.redhat.com/show_bug.cgi?id=1486220
- https://github.com/gottburgm/Exploits/tree/master/CVE-2017-12149
- http://www.securityfocus.com/bid/100591
- https://access.redhat.com/errata/RHSA-2018:1607
- https://access.redhat.com/errata/RHSA-2018:1608
- https://bugzilla.redhat.com/show_bug.cgi?id=1486220
- https://github.com/gottburgm/Exploits/tree/master/CVE-2017-12149
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12149
→ the Explorer · watch your stack · NVD