Red Hat JBoss Enterprise Application Platform(EAP)是美国红帽(Red Hat)公司的一套开源、基于J2EE的中间件平台。该平台主要用于构建、部署和托管Java应用程序与服务。Jboss Application Server是其中的一款基于JavaEE的开源的应用服务器。 Red Hat Jboss EAP 5.0版本中附带的Jboss Application Server存在远程代码执行漏洞。远程攻击者可借助特制的序列化数据利用该漏洞在受影响应用程序上下文
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat, Inc. | jbossas | n/a |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat, Inc. | jbossas | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2017-12149 JBOSS as 6.X反序列化(反弹shell版) | https://github.com/sevck/CVE-2017-12149 | POC Details |
| 2 | CVE-2017-12149 jboss反序列化 可回显 | https://github.com/yunxu1/jboss-_CVE-2017-12149 | POC Details |
| 3 | CVE-2017-12149 JBOSS RCE (TESTED) | https://github.com/1337g/CVE-2017-12149 | POC Details |
| 4 | Jboss Java Deserialization RCE (CVE-2017-12149) | https://github.com/jreppiks/CVE-2017-12149 | POC Details |
| 5 | JBoss CVE-2017-12149 (Insecure Deserialization - RCE) Exploitation Lab. | https://github.com/Xcatolin/jboss-deserialization | POC Details |
| 6 | None | https://github.com/VVeakee/CVE-2017-12149 | POC Details |
| 7 | None | https://github.com/MrE-Fog/jboss-_CVE-2017-12149 | POC Details |
| 8 | Update of https://github.com/1337g/CVE-2017-12149 to work with python3 | https://github.com/JesseClarkND/CVE-2017-12149 | POC Details |
| 9 | None | https://github.com/zesnd/cve-2017-12149 | POC Details |
| 10 | Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2 is susceptible to a remote code execution vulnerability because the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization, thus allowing an attacker to execute arbitrary code via crafted serialized data. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2017/CVE-2017-12149.yaml | POC Details |
| 11 | None | https://github.com/Threekiii/Awesome-POC/blob/master/%E4%B8%AD%E9%97%B4%E4%BB%B6%E6%BC%8F%E6%B4%9E/JBoss%205.x6.x%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E%20CVE-2017-12149.md | POC Details |
| 12 | https://github.com/vulhub/vulhub/blob/master/jboss/CVE-2017-12149/README.md | POC Details | |
| 13 | None | https://github.com/Threekiii/Awesome-POC/blob/master/%E4%B8%AD%E9%97%B4%E4%BB%B6%E6%BC%8F%E6%B4%9E/JBoss%205.x%206.x%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E%20CVE-2017-12149.md | POC Details |
| 14 | None | https://github.com/galois17/cve-2017-12149-playground | POC Details |
No public POC found.
Login to generate AI POCNo comments yet