Critical severity9.8NVD Advisory· Published May 19, 2017· Updated May 13, 2026
CVE-2017-7504
CVE-2017-7504
Description
HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Server <= Jboss 4.X does not restrict the classes for which it performs deserialization, which allows remote attackers to execute arbitrary code via crafted serialized data.
Affected products
2- cpe:2.3:a:redhat:jboss_enterprise_application_platform:*:*:*:*:*:*:*:*Range: <=4.0
- Red Hat, Inc./JBossv5Range: 4.x
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/bid/98595nvdThird Party AdvisoryVDB Entry
- bugzilla.redhat.com/show_bug.cginvdIssue Tracking
News mentions
0No linked articles in our index yet.