CVE-2017-12149
CRITICAL(9.8)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS 9.8 — Kritisch
- EPSS 91% — sehr wahrscheinlich ausgenutzt
- Im CISA KEV-Katalog (aktiv ausgenutzt)
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
90.7%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
9.8
Technische Schwere
SecBoard-Einordnung
CVE-2017-12149 betrifft den JBoss Application Server, wie er mit Red Hat Enterprise Application Platform 5.2 ausgeliefert wird. Die Schwachstelle liegt in der doFilter-Methode des ReadOnlyAccessFilter des HTTP Invokers, welche die Deserialisierung von Klassen nicht ausreichend einschränkt. Dies ermöglicht einem Angreifer die Ausführung von beliebigem Code durch speziell präparierte serialisierte Daten.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.
Betroffene Produkte
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:-:*:*:*:text-only:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.2.2:*:*:*:*:*:*:*
Referenzen
- http://www.securityfocus.com/bid/100591
- https://access.redhat.com/errata/RHSA-2018:1607
- https://access.redhat.com/errata/RHSA-2018:1608
- https://bugzilla.redhat.com/show_bug.cgi?id=1486220
- https://github.com/gottburgm/Exploits/tree/master/CVE-2017-12149
- http://www.securityfocus.com/bid/100591
- https://access.redhat.com/errata/RHSA-2018:1607
- https://access.redhat.com/errata/RHSA-2018:1608
- https://bugzilla.redhat.com/show_bug.cgi?id=1486220
- https://github.com/gottburgm/Exploits/tree/master/CVE-2017-12149