CVE-2017-7504
HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Server <= Jboss 4.X does not restrict the classes for which it performs deserialization, which allows remote attackers to execute arbitrary code via crafted serialized data.
- Affected products
- Jboss Application Server, Jbossmq
- Redhat Jboss Enterprise Application Platform
- ≤ 4.0
- Fix
- Available
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 41.0% (99th percentile)
- Weakness
- CWE-502
- NVD status
- Modified
- Published
- 2017-05-19
CVE-2017-7504 at NVD
7 known exploits for CVE-2017-7504
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2017-7504-poc
CVE-2015-7501
Exploit for Deserialization of Untrusted Data in Redhat Data_Grid
JBOSSAS 4.x Deserializer Vulnerability
JBOSSAS 4.x 反序列化命令执行漏洞(CVE-2017-7504)
Exploit for Deserialization of Untrusted Data in Redhat Jboss_Enterprise_Application_Platform
Immunity Canvas: JBOSSMQ_HTTPIL_DESERIALIZATION