← All CVEs

CVE-2017-12149

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2021-12-10Remediation due 2022-06-10

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.

9.8
CVSS
90.7%
EPSS (exploit prob.)
100th
EPSS percentile
2017-10-04
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-502

Affected products

VendorProductAffected versions
redhatjboss_enterprise_application_platformall versions
redhatjboss_enterprise_application_platform5.0.0
redhatjboss_enterprise_application_platform5.0.1
redhatjboss_enterprise_application_platform5.1.0
redhatjboss_enterprise_application_platform5.1.1
redhatjboss_enterprise_application_platform5.1.2
redhatjboss_enterprise_application_platform5.2.0
redhatjboss_enterprise_application_platform5.2.1
redhatjboss_enterprise_application_platform5.2.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-12149