CVE-2017-7504
19.05.2017, 20:29
HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Server <= Jboss 4.X does not restrict the classes for which it performs deserialization, which allows remote attackers to execute arbitrary code via crafted serialized data.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | jboss_enterprise_application_platform | 𝑥 ≤ 4.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration