Executive brief
The doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker in Red Hat JBoss Application Server does not restrict classes during deserialization. This allows unauthenticated remote attackers to execute arbitrary code via crafted serialized data.
Affected products
- Red Hat JBoss Application Server 5.2.0, 5.2.1, 5.2.2
- Red Hat Enterprise Application Platform 5.0.0, 5.0.1, 5.1.0, 5.1.1, 5.1.2, 5.2.0, 5.2.1, 5.2.2
Timeline
- 2017-08-30: disclosed: Date based on Red Hat Bugzilla ID 1486220 creation or related BID 100591
- 2018-05-19: patched: Red Hat errata RHSA-2018:1607 and RHSA-2018:1608 released.
- 2021-12-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.