CVE-2017-5983
9.8
CRITICAL · CVSS 3.0 · EPSS 16.2% (pctl 97)
Patch early
EPSS 16.2% — above the 10% action threshold.
Description
The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 16.24% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-502 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-04-10 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| atlassian | jira |
References
- http://codewhitesec.blogspot.com/2017/04/amf.html
- http://www.securityfocus.com/bid/97379
- https://confluence.atlassian.com/jira063/jira-security-advisory-2017-03-09-875604401.html
- https://jira.atlassian.com/browse/JRASERVER-64077
- https://www.kb.cert.org/vuls/id/307983
- http://codewhitesec.blogspot.com/2017/04/amf.html
- http://www.securityfocus.com/bid/97379
- https://confluence.atlassian.com/jira063/jira-security-advisory-2017-03-09-875604401.html
- https://jira.atlassian.com/browse/JRASERVER-64077
- https://www.kb.cert.org/vuls/id/307983
→ the Explorer · watch your stack · NVD