CVE Database
/

CVE-2013-2165

Back to search

CVE-2013-2165

Published: Jul 22, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss Enterprise Application Platform through 4.3.0 CP10 and 5.x through 5.2.0, Red Hat JBoss BRMS through 5.3.1, Red Hat JBoss SOA Platform through 4.3.0 CP05 and 5.x through 5.3.1, Red Hat JBoss Portal through 4.3 CP07 and 5.x through 5.2.2, and Red Hat JBoss Operations Network through 2.4.2 and 3.x through 3.1.2 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data.

VendorProductVersions

n/a

n/a

affected
n/a

References

JVN#38787103
third-party-advisory
x_refsource_JVN
RHSA-2013:1045
vendor-advisory
x_refsource_REDHAT
RHSA-2013:1041
vendor-advisory
x_refsource_REDHAT
RHSA-2013:1043
vendor-advisory
x_refsource_REDHAT
RHSA-2013:1044
vendor-advisory
x_refsource_REDHAT
JVNDB-2013-000072
third-party-advisory
x_refsource_JVNDB
RHSA-2013:1042
vendor-advisory
x_refsource_REDHAT
20200313 RichFaces exploitation toolkit
mailing-list
x_refsource_FULLDISC

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now