Sploitus

CVE-2017-7504

7 known exploits for CVE-2017-7504

HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Server <= Jboss 4.X does not restrict the classes for which it performs deserialization, which allows remote attackers to execute arbitrary code via crafted serialized data.

Redhat Jboss Enterprise Application Platform
≤ 4.0
Fix
Available
CVSS 3.0
9.8 CRITICAL
EPSS
41.0% (99th percentile)
Weakness
CWE-502
NVD status
Modified
Published
2017-05-19
CVE-2017-7504 at NVD
Authoritative description, scoring and affected products

7 known exploits for CVE-2017-7504

Proof-of-concept code and exploit modules indexed by Sploitus