CVE Database
/

CVE-2017-12149

Back to search

CVE-2017-12149

Published: Oct 4, 2017

Modified: Oct 21, 2025

PUBLISHED

Description

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.

VendorProductVersions

Red Hat, Inc.

jbossas

affected
n/a

Weaknesses (CWE)

References

RHSA-2018:1608
vendor-advisory
x_refsource_REDHAT
100591
vdb-entry
x_refsource_BID
RHSA-2018:1607
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now