vendor:
JBoss EAP
by:
Federico Dotta, Maurizio Agazzini
8,8
CVSS
HIGH
Deserialization of untrusted data
502
CWE
Product Name: JBoss EAP
Affected Version From: JBoss EAP 5.2.X and prior versions
Affected Version To: JBoss EAP 5.2.X and prior versions
Patch Exists: NO
Related CWE: CVE-2016-7065
CPE: a:redhat:jboss_enterprise_application_platform:5.2.0
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2016
Red Hat JBoss EAP deserialization of untrusted data
The application server deserializes untrusted data via the JMX Invoker Servlet. This can lead to a DoS via resource exhaustion and potentially remote code execution.
Mitigation:
The vendor has decided not to fix this issue.