Record summary

CVE-2017-7504 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC.

Description

HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Server <= Jboss 4.X does not restrict the classes for which it performs deserialization, which allows remote attackers to execute arbitrary code via crafted serialized data.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 23, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
CVE List4.xaffected

Proofs of concept

1

Repository PoCs

GitHubwudidwo/CVE-2017-7504-pocRepository PoCby wudidwoStars: 0Not analyzed2 files

1.0 KiB

GitHub

PoC details

References

3