RichFaces: Remote code execution due to insecure deserialization
Published Jul 22, 2013
7.5
HIGHCVSS 2.0
EPSS 12.66%
Description
ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss Enterprise Application Platform through 4.3.0 CP10 and 5.x through 5.2.0, Red Hat JBoss BRMS through 5.3.1, Red Hat JBoss SOA Platform through 4.3.0 CP05 and 5.x through 5.3.1, Red Hat JBoss Portal through 4.3 CP07 and 5.x through 5.2.2, and Red Hat JBoss Operations Network through 2.4.2 and 3.x through 3.1.2 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data.
Affected products
No data.
- 4.3.0
- 4.3.0
- 5.0.0
- 5.0.1
- 5.1.0
- 5.1.1
- 5.1.2
- 5.2.0
- 5.0.0
- 5.0.1
- 5.0.2
- 5.1.0
- 5.2.0
- 5.3.0
- 5.3.1
- 4.3.0
- 4.3.0
- 4.3.0
- 4.3.0
- 4.3.0
- 5.0.0
- 5.0.1
- 5.1.0
- 5.1.1
- 5.2.0
- 5.2.1
- 5.2.2
- 4.2.0
- 4.2.0
- 4.2.0
- 4.2.0
- 4.2.0
- 4.2.0
- 4.2.0
- 4.3.0
- 4.3.0
- 4.3.0
- 4.3.0
- 4.3.0
- 4.3.0
- 5.0.0
- 5.0.1
- 5.0.2
- 5.1.0
- 5.1.1
- 5.2.0
- 5.3.0
- 5.3.1
- 5.1.0
- 5.1.1
- 5.1.2
- 5.2.0
- 1.0.0
- 2.0.0
- 2.0.1
- 2.1.0
- 2.2
- 2.3
- 2.3.1
- 2.4
- 2.4.1
- 2.4.2
- 3.0
- 3.0.1
- 3.1
- 3.1.1
- 3.1.2
- ≤ 2.2.0
- 1.0.0
- 1.1.0
- 1.2.0
- 2.0.0
- 2.1.0
- 3.1.0
- 3.1.1
- 3.1.2
- 3.1.3
- 3.1.4
- 3.1.5
- 3.1.6
- 3.2.0
- 3.2.0
- 3.2.1
- 3.2.2
- 3.3.0
- 3.3.1
- 3.3.2
- 3.3.2
- 3.3.3
- 4.0.0
- 4.1.0
- 4.2.0
- 4.2.1
- 4.2.2
- 4.2.3
- 4.3.0
- 4.3.1
- 4.5.0
- 5.0.0
No data.
JBEWP 5 for RHEL 5
richfaces-0:3.3.1-6.SP3_patch_01.ep5.el5
Fixed · RHSA-2013:1043
JBEWP 5 for RHEL 6
richfaces-0:3.3.1-3.SP3_patch_01.ep5.el6
Fixed · RHSA-2013:1043
JBoss Enterprise BRMS Platform 5.3
n/a
Fixed · RHSA-2013:1045
Red Hat JBoss Enterprise Application Platform 4.3
n/a
Fixed · RHSA-2013:1045
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jboss-seam2-0:2.0.2.FP_SEC1-1.ep2.6.el4
Fixed · RHSA-2013:1044
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jboss-seam2-0:2.0.2.FP_SEC1-1.ep2.6.el5
Fixed · RHSA-2013:1044
Red Hat JBoss Enterprise Application Platform 5 for RHEL 4
richfaces-0:3.3.1-11.SP3_patch_01.ep5.el4
Fixed · RHSA-2013:1042
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5
richfaces-0:3.3.1-6.SP3_patch_01.ep5.el5
Fixed · RHSA-2013:1042
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6
richfaces-0:3.3.1-3.SP3_patch_01.ep5.el6
Fixed · RHSA-2013:1042
Red Hat JBoss Enterprise Application Platform 5.2
n/a
Fixed · RHSA-2013:1045
Red Hat JBoss Operations Network 2.4
n/a
Fixed · RHSA-2013:1045
Red Hat JBoss Operations Network 3.1
n/a
Fixed · RHSA-2013:1045
Red Hat JBoss Portal 4.3
n/a
Fixed · RHSA-2013:1045
Red Hat JBoss Portal 5.2
n/a
Fixed · RHSA-2013:1045
Red Hat JBoss SOA Platform 4.3
n/a
Fixed · RHSA-2013:1045
Red Hat JBoss SOA Platform 5.3
n/a
Fixed · RHSA-2013:1045
Red Hat JBoss Web Framework Kit 2.3
n/a
Fixed · RHSA-2013:1041
Red Hat JBoss Web Platform 5.2
n/a
Fixed · RHSA-2013:1045
Red Hat JBoss BRMS 5
RichFaces
Affected
Red Hat JBoss Operations Network 2
RichFaces
Affected
Red Hat JBoss Operations Network 3
RichFaces
Affected
Red Hat JBoss Portal 4
RichFaces
Affected
Red Hat JBoss Portal 5
RichFaces
Affected
Red Hat JBoss SOA Platform 4
RichFaces
Affected
Red Hat JBoss SOA Platform 5
RichFaces
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| JBEWP 5 for RHEL 5 | richfaces-0:3.3.1-6.SP3_patch_01.ep5.el5 | Fixed | RHSA-2013:1043 |
| JBEWP 5 for RHEL 6 | richfaces-0:3.3.1-3.SP3_patch_01.ep5.el6 | Fixed | RHSA-2013:1043 |
| JBoss Enterprise BRMS Platform 5.3 | n/a | Fixed | RHSA-2013:1045 |
| Red Hat JBoss Enterprise Application Platform 4.3 | n/a | Fixed | RHSA-2013:1045 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jboss-seam2-0:2.0.2.FP_SEC1-1.ep2.6.el4 | Fixed | RHSA-2013:1044 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jboss-seam2-0:2.0.2.FP_SEC1-1.ep2.6.el5 | Fixed | RHSA-2013:1044 |
| Red Hat JBoss Enterprise Application Platform 5 for RHEL 4 | richfaces-0:3.3.1-11.SP3_patch_01.ep5.el4 | Fixed | RHSA-2013:1042 |
| Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 | richfaces-0:3.3.1-6.SP3_patch_01.ep5.el5 | Fixed | RHSA-2013:1042 |
| Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 | richfaces-0:3.3.1-3.SP3_patch_01.ep5.el6 | Fixed | RHSA-2013:1042 |
| Red Hat JBoss Enterprise Application Platform 5.2 | n/a | Fixed | RHSA-2013:1045 |
| Red Hat JBoss Operations Network 2.4 | n/a | Fixed | RHSA-2013:1045 |
| Red Hat JBoss Operations Network 3.1 | n/a | Fixed | RHSA-2013:1045 |
| Red Hat JBoss Portal 4.3 | n/a | Fixed | RHSA-2013:1045 |
| Red Hat JBoss Portal 5.2 | n/a | Fixed | RHSA-2013:1045 |
| Red Hat JBoss SOA Platform 4.3 | n/a | Fixed | RHSA-2013:1045 |
| Red Hat JBoss SOA Platform 5.3 | n/a | Fixed | RHSA-2013:1045 |
| Red Hat JBoss Web Framework Kit 2.3 | n/a | Fixed | RHSA-2013:1041 |
| Red Hat JBoss Web Platform 5.2 | n/a | Fixed | RHSA-2013:1045 |
| Red Hat JBoss BRMS 5 | RichFaces | Affected | n/a |
| Red Hat JBoss Operations Network 2 | RichFaces | Affected | n/a |
| Red Hat JBoss Operations Network 3 | RichFaces | Affected | n/a |
| Red Hat JBoss Portal 4 | RichFaces | Affected | n/a |
| Red Hat JBoss Portal 5 | RichFaces | Affected | n/a |
| Red Hat JBoss SOA Platform 4 | RichFaces | Affected | n/a |
| Red Hat JBoss SOA Platform 5 | RichFaces | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (14)
- http://jvn.jp/en/jp/JVN38787103/index.html third-party-advisoryx_refsource_JVNThird Party AdvisoryVDB Entry
- http://jvndb.jvn.jp/jvndb/JVNDB-2013-000072 third-party-advisoryx_refsource_JVNDBThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/156663/Richsploit-RichFaces-Exploitation-Toolkit.html x_refsource_MISC
- http://rhn.redhat.com/errata/RHSA-2013-1041.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1042.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1043.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1044.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1045.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://seclists.org/fulldisclosure/2020/Mar/21 mailing-listx_refsource_FULLDISC
- https://access.redhat.com/security/cve/CVE-2013-2165 x_refsource_CONFIRMVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=973570 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://github.com/advisories/GHSA-4344-frcp-j22q Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-2165
- https://www.cve.org/CVERecord?id=CVE-2013-2165
Change history (0)
No recorded changes yet.