The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1382534 | issue tracking vendor advisory |
https://www.exploit-db.com/exploits/40842/ | exploit |
http://seclists.org/fulldisclosure/2016/Nov/143 | mailing list |
http://www.securityfocus.com/bid/93462 | vdb entry third party advisory |