CVE-2017-12149
KEV ransomwarelargeUnauthenticated Deserialization RCE in Red Hat JBoss EAP 5.2 HTTP Invoker
CISA: Red Hat JBoss Application Server Remote Code Execution Vulnerability
CVE-2017-12149 is a critical (CVSS 9.8) unauthenticated deserialization flaw in the doFilter method of the ReadOnlyAccessFilter of the HTTP Invoker in JBoss Application Server as shipped with Red Hat Enterprise Application Platform 5.2 (CWE-502). Because the filter does not restrict which classes it will deserialize, a remote, unauthenticated attacker can send crafted serialized data to the HTTP Invoker endpoint over the network and have the server deserialize it. Successful exploitation yields arbitrary code execution with the privileges of the JBoss server process, giving attackers a foothold for full system compromise. Any organization running the affected JBoss Application Server/EAP 5.2 with the HTTP Invoker enabled is affected. The flaw is actively exploited: it is in CISA's Known Exploited Vulnerabilities Catalog (added 2021-12-10) with known ransomware use, EPSS estimates a 90.7% chance of exploitation within 30 days, and reporting links it to campaigns by the ChamelGang APT group against energy and aviation targets.
What to do: Per the KEV required action, apply the vendor's updates to Red Hat JBoss EAP following Red Hat's instructions. As an interim mitigation, restrict or remove access to the HTTP Invoker endpoints (for example, block or firewall the invoker paths so they are not reachable by untrusted clients). Prioritize patching on internet-facing JBoss servers and hunt for signs of exploitation, given the known ransomware use.
| Red Hat JBoss Enterprise Application Platform (JBoss Application Server, HTTP Invoker ReadOnlyAccessFilter) | as shipped with Red Hat Enterprise Application Platform 5.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.
- Affected
- Red Hat JBoss Application Server
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- redhat
- Products
- jboss enterprise application platform
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H