Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-2165

Опубликовано: 10 июл. 2013
Источник: redhat
CVSS2: 7.5
EPSS Средний

Описание

ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss Enterprise Application Platform through 4.3.0 CP10 and 5.x through 5.2.0, Red Hat JBoss BRMS through 5.3.1, Red Hat JBoss SOA Platform through 4.3.0 CP05 and 5.x through 5.3.1, Red Hat JBoss Portal through 4.3 CP07 and 5.x through 5.2.2, and Red Hat JBoss Operations Network through 2.4.2 and 3.x through 3.1.2 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5RichFacesAffected
Red Hat JBoss Operations Network 2RichFacesAffected
Red Hat JBoss Operations Network 3RichFacesAffected
Red Hat JBoss Portal 4RichFacesAffected
Red Hat JBoss Portal 5RichFacesAffected
Red Hat JBoss SOA Platform 4RichFacesAffected
Red Hat JBoss SOA Platform 5RichFacesAffected
JBEWP 5 for RHEL 5richfacesFixedRHSA-2013:104310.07.2013
JBEWP 5 for RHEL 6richfacesFixedRHSA-2013:104310.07.2013
JBoss Enterprise BRMS Platform 5.3FixedRHSA-2013:104511.07.2013

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=973570RichFaces: Remote code execution due to insecure deserialization

EPSS

Процентиль: 96%
0.12662
Средний

7.5 High

CVSS2

Связанные уязвимости

ubuntu
около 13 лет назад

ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss Enterprise Application Platform through 4.3.0 CP10 and 5.x through 5.2.0, Red Hat JBoss BRMS through 5.3.1, Red Hat JBoss SOA Platform through 4.3.0 CP05 and 5.x through 5.3.1, Red Hat JBoss Portal through 4.3 CP07 and 5.x through 5.2.2, and Red Hat JBoss Operations Network through 2.4.2 and 3.x through 3.1.2 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data.

nvd
около 13 лет назад

ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss Enterprise Application Platform through 4.3.0 CP10 and 5.x through 5.2.0, Red Hat JBoss BRMS through 5.3.1, Red Hat JBoss SOA Platform through 4.3.0 CP05 and 5.x through 5.3.1, Red Hat JBoss Portal through 4.3 CP07 and 5.x through 5.2.2, and Red Hat JBoss Operations Network through 2.4.2 and 3.x through 3.1.2 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data.

debian
около 13 лет назад

ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementati ...

github
около 4 лет назад

Remote code execution due to insecure deserialization

EPSS

Процентиль: 96%
0.12662
Средний

7.5 High

CVSS2