jbossas: Arbitrary code execution via unrestricted deserialization in ReadOnlyAccessFilter of HTTP Invoker.
Published Oct 4, 2017 ·Due Jun 10, 2022
9.8
CRITICALCVSS 3.1
EPSS 90.71%
Description
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat, Inc. | Jbossas | n/a |
|
- n/a
- 5.0.0
- 5.0.1
- 5.1.0
- 5.1.1
- 5.1.2
- 5.2.0
- 5.2.1
- 5.2.2
No data.
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5
jbossas-0:5.2.0-24.ep5.el5
Fixed · RHSA-2018:1607
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6
jbossas-0:5.2.0-24.ep5.el6
Fixed · RHSA-2018:1607
Red Hat JBoss Enterprise Application Platform 5.2 security update
eap-parent
Fixed · RHSA-2018:1608
Red Hat JBoss Enterprise Application Platform 6
eap-parent
Not affected
Red Hat JBoss Enterprise Application Platform 7
eap-parent
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 | jbossas-0:5.2.0-24.ep5.el5 | Fixed | RHSA-2018:1607 |
| Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 | jbossas-0:5.2.0-24.ep5.el6 | Fixed | RHSA-2018:1607 |
| Red Hat JBoss Enterprise Application Platform 5.2 security update | eap-parent | Fixed | RHSA-2018:1608 |
| Red Hat JBoss Enterprise Application Platform 6 | eap-parent | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | eap-parent | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat JBoss Enterprise Application Platform 6 and 7 do not ship the http invoker so they are not affected.
Red Hat mitigation
Secure the access to the entire http-invoker contexts by adding <url-pattern>/*</url-pattern> to the security-constraints in the web.xml file of the http-invoker.sar.The users who do not wish to use the http-invoker.sar can remove it.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
Date Added
Dec 10, 2021
Patch Due
Jun 10, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Feb 7, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (15 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 90.71% (0.90713) | 99.80th | v5 (v2026.06.15) |
| Jun 15, 2026 | 90.71% (0.90713) | 99.79th | v5 (v2026.06.15) |
| Mar 17, 2025 | 94.31% (0.94313) | 99.94th | v4 (v2025.03.14) |
| Dec 17, 2024 | 95.60% (0.95599) | 99.56th | v3 (v2023.03.01) |
| Jul 25, 2024 | 93.81% (0.93810) | 99.16th | v3 (v2023.03.01) |
| Sep 14, 2023 | 97.19% (0.97190) | 99.73th | v3 (v2023.03.01) |
| Aug 14, 2023 | 97.29% (0.97292) | 99.78th | v3 (v2023.03.01) |
| May 24, 2023 | 97.40% (0.97400) | 99.86th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.43% (0.97427) | 99.87th | v3 (v2023.03.01) |
| Mar 6, 2023 | 51.19% (0.51193) | 98.73th | v2 (v2022.01.01) |
| Jul 1, 2022 | 51.19% (0.51193) | 98.61th | v2 (v2022.01.01) |
| Feb 4, 2022 | 53.91% (0.53906) | 98.43th | v2 (v2022.01.01) |
| Feb 3, 2022 | 42.46% (0.42459) | 98.71th | v1 |
| Sep 1, 2021 | 42.46% (0.42459) | 99.36th | v1 |
| Apr 14, 2021 | 42.46% (0.42459) | 0.00th | v1 |
References (10)
- http://www.securityfocus.com/bid/100591 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:1607 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1608 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-12149 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1486220 x_refsource_CONFIRMIssue Tracking
- https://github.com/gottburgm/Exploits/tree/master/CVE-2017-12149 x_refsource_MISCThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-12149
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12149 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2017-12149
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/100591 | vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/errata/RHSA-2018:1607 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2018:1608 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2017-12149 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1486220 | x_refsource_CONFIRMIssue Tracking | |
| https://github.com/gottburgm/Exploits/tree/master/CVE-2017-12149 | x_refsource_MISCThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-12149 | ||
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog | ||
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12149 | government-resourceUS Government Resource | |
| https://www.cve.org/CVERecord?id=CVE-2017-12149 |
Change history (0)
No recorded changes yet.