Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-3708

Опубликовано: 01 дек. 2010
Источник: redhat
CVSS2: 7.5
EPSS Низкий

Описание

The serialization implementation in JBoss Drools in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 and JBoss Enterprise SOA Platform 4.2 and 4.3 supports the embedding of class files, which allows remote attackers to execute arbitrary code via a crafted static initializer.

Дополнительная информация

Статус:

Important
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=633859JBoss drools deserialization remote code execution

EPSS

Процентиль: 85%
0.02416
Низкий

7.5 High

CVSS2

Связанные уязвимости

ubuntu
около 15 лет назад

The serialization implementation in JBoss Drools in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 and JBoss Enterprise SOA Platform 4.2 and 4.3 supports the embedding of class files, which allows remote attackers to execute arbitrary code via a crafted static initializer.

nvd
около 15 лет назад

The serialization implementation in JBoss Drools in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 and JBoss Enterprise SOA Platform 4.2 and 4.3 supports the embedding of class files, which allows remote attackers to execute arbitrary code via a crafted static initializer.

debian
около 15 лет назад

The serialization implementation in JBoss Drools in Red Hat JBoss Ente ...

github
больше 3 лет назад

Drools Improper Input Validation vulnerability allows remote attackers to execute arbitrary code in JBoss EAP

EPSS

Процентиль: 85%
0.02416
Низкий

7.5 High

CVSS2