Skip to content

Files

Latest commit

 

History

History

CVE-2017-12149

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 

text-white

Description :

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.

Type :

Deserialization of Untrusted Data

CVE :

CVE-2017-12149

Affected Versions :

  • 5.2

References :