Back

CRITICAL

PooledInvokerServlet is not secured, and deserializes data

Published Jun 8, 2017

Description

The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.

Affected products

Remediation

Red Hat mitigation

The PooledInvokerServlet is no longer required and can be removed by following the details in this knowledgebase solution: https://access.redhat.com/solutions/178393

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 8, 2017
Updated Aug 6, 2024
Reserved Mar 30, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jun 13, 2016