In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HRed Hat Jboss Enterprise Application Platform
APPRedhat5.0.05.0.15.1.05.1.15.1.25.2.05.2.15.2.2
CISA KEV — detailsi
- Vendori
- Red Hat ↗
- Producti
- JBoss Application Server
- Added to KEVi
- December 10, 2021
- Remediation deadline (US Federal)i
- June 10, 2022(overdue)
- Ransomwarei
- Active ransomware campaigns exploit this vulnerability
Apply updates per vendor instructions.
The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data.
Related vulnerabilities
Brak walidacji nagłówka Host w serwerze Undertow HTTP
Wildfly: ignorowanie 'enabled-protocols' umożliwia TLS downgrade
RCE poprzez deserializację JNDI w jackson-databind (commons-configuration)
Netty: nieprawidłowe parsowanie nagłówków HTTP bez dwukropka (HTTP Request Smuggling)
Netty: HTTP Request Smuggling przez duplikat nagłówka Content-Length