ZeroHour

CVE-2017-12149

KEV ransomwarelarge

Unauthenticated Deserialization RCE in Red Hat JBoss EAP 5.2 HTTP Invoker

CISA: Red Hat JBoss Application Server Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
91%p100
Published
()
KEV added
AI analysis

CVE-2017-12149 is a critical (CVSS 9.8) unauthenticated deserialization flaw in the doFilter method of the ReadOnlyAccessFilter of the HTTP Invoker in JBoss Application Server as shipped with Red Hat Enterprise Application Platform 5.2 (CWE-502). Because the filter does not restrict which classes it will deserialize, a remote, unauthenticated attacker can send crafted serialized data to the HTTP Invoker endpoint over the network and have the server deserialize it. Successful exploitation yields arbitrary code execution with the privileges of the JBoss server process, giving attackers a foothold for full system compromise. Any organization running the affected JBoss Application Server/EAP 5.2 with the HTTP Invoker enabled is affected. The flaw is actively exploited: it is in CISA's Known Exploited Vulnerabilities Catalog (added 2021-12-10) with known ransomware use, EPSS estimates a 90.7% chance of exploitation within 30 days, and reporting links it to campaigns by the ChamelGang APT group against energy and aviation targets.

What to do: Per the KEV required action, apply the vendor's updates to Red Hat JBoss EAP following Red Hat's instructions. As an interim mitigation, restrict or remove access to the HTTP Invoker endpoints (for example, block or firewall the invoker paths so they are not reachable by untrusted clients). Prioritize patching on internet-facing JBoss servers and hunt for signs of exploitation, given the known ransomware use.

Affected
Red Hat JBoss Enterprise Application Platform (JBoss Application Server, HTTP Invoker ReadOnlyAccessFilter)as shipped with Red Hat Enterprise Application Platform 5.2
Estimated exposure
largeroughly tens of thousands of internet-exposed JBoss HTTP Invoker servers (estimate) — No install counts were provided, so this is estimated from public internet scanning, which has historically shown tens of thousands of JBoss hosts exposing the HTTP Invoker endpoint, with EAP 5.x remaining on legacy deployments.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.

CISA Known Exploited Vulnerability
Affected
Red Hat JBoss Application Server
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
redhat
Products
jboss enterprise application platform
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news