CVE-2017-7504

CRITICAL EXPLOITED

Jboss <4.X - Code Injection

Title source: llm

Description

HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Server <= Jboss 4.X does not restrict the classes for which it performs deserialization, which allows remote attackers to execute arbitrary code via crafted serialized data.

Exploits (1)

nomisec SCANNER
by wudidwo · poc
https://github.com/wudidwo/CVE-2017-7504-poc

Scores

CVSS v3 9.8
EPSS 0.9028
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

VulnCheck KEV 2023-03-23

Classification

CWE
CWE-502
Status draft

Affected Products (1)

redhat/jboss_enterprise_application_platform < 4.0

Timeline

Published May 19, 2017
Tracked Since Feb 18, 2026