Back

CRITICAL KEV Used in ransomware campaigns

jbossas: Arbitrary code execution via unrestricted deserialization in ReadOnlyAccessFilter of HTTP Invoker.

Published Oct 4, 2017 ·Due Jun 10, 2022

Description

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.

Affected products

Remediation

Red Hat statement

Red Hat JBoss Enterprise Application Platform 6 and 7 do not ship the http invoker so they are not affected.

Red Hat mitigation

Secure the access to the entire http-invoker contexts by adding <url-pattern>/*</url-pattern> to the security-constraints in the web.xml file of the http-invoker.sar.The users who do not wish to use the http-invoker.sar can remove it.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 4, 2017
Updated Aug 13, 2026
Reserved Aug 1, 2017
CISA Vulnrichment
Updated Feb 7, 2025
NVD
Status Analyzed
Modified Aug 13, 2026
Red Hat
Severity Critical
Public date Aug 30, 2017