JBoss RichFaces Deserialization Vulnerability
RISK: Medium Risk
TYPE: Servers - Internet App Servers
A vulnerability has been identified in JBoss, which can be exploited by remote user to execute arbitrary code on the target system. A remote user can send specially crafted data to trigger a flaw in the way RichFaces ResourceBuilderImpl handles deserialization and potentially execute arbitrary code on the target system. The code will run with the privileges of the target service.
Impact
- Remote Code Execution
System / Technologies affected
- JBoss Enterprise Application Platform 4.3.0 EL4
- JBoss Enterprise Application Platform 4.3.0 EL5
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Apply vendor fix
Vulnerability Identifier
Source
Related Link
Share with