The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1327037 | issue tracking vendor advisory |
https://access.redhat.com/solutions/45530 | mitigation vendor advisory |
http://www.securityfocus.com/bid/99079 | vdb entry third party advisory |
https://access.redhat.com/solutions/178393 | mitigation vendor advisory |