CVE-2017-12149
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- August 01, 2017
- Published Date
- October 04, 2017
- Last Updated
- February 07, 2025
- Vendor
- Red Hat, Inc.
- Product
- jbossas
- Description
- In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.
CVSS Scores
SSVC Information
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- total
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2021-12-10 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2017/CVE-2017-12149.yaml | 2025-04-26 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
JesseClarkND/CVE-2017-12149
Type: github • Created: 2024-04-30 18:40:48 UTC • Stars: 0
MrE-Fog/jboss-_CVE-2017-12149
Type: github • Created: 2023-08-06 12:11:43 UTC • Stars: 0
VVeakee/CVE-2017-12149
Type: github • Created: 2022-04-14 13:24:51 UTC • Stars: 0
jreppiks/CVE-2017-12149
Type: github • Created: 2019-08-22 21:06:09 UTC • Stars: 12
1337g/CVE-2017-12149
Type: github • Created: 2017-12-22 07:30:29 UTC • Stars: 15
yunxu1/jboss-_CVE-2017-12149
Type: github • Created: 2017-11-28 02:52:47 UTC • Stars: 206
sevck/CVE-2017-12149
Type: github • Created: 2017-11-21 10:48:24 UTC • Stars: 22