Skip to main content
CISA Known Exploited Vulnerabilities

Red Hat JBoss Application Server Remote Code Execution Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.

Added to KEV
2021-12-10
Remediation due
2022-06-10
Ransomware
Known use

Required action
Apply updates per vendor instructions.

CISA notes
https://nvd.nist.gov/vuln/detail/CVE-2017-12149

Description

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.

Severity

CVSS 3.1 · CISA9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC · CISA-ADP
Exploitationactive
Automatableyes
Technical impacttotal

Affected Products

VendorProductAffected versions
Red Hat, Inc.jbossas
n/a

References

5 Links

Record Details

Published
2017-10-04
Last updated
2026-08-13
Assigner (CNA)
redhat
Credited to
-

Related Tool Categories

Tool categories that test for or protect against this vulnerability class.

CWE-502 · Deserialization of Untrusted Data

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.