December 10, 2021 · Applied Cybernetics Group
CVE-2017-12149 — Red Hat JBoss Application Server
known ransomware use
Red Hat JBoss Application Server Remote Code Execution Vulnerability
- Added to KEV
2021-12-10- Federal due date
2022-06-10- Vendor
- Red Hat
- Product
- JBoss Application Server
- EPSS
- 99.8th percentile (score 0.907, as of
2026-09-16) - NVD CVSS v3.1
- 9.8 (CRITICAL)
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2017-12149
CISA short description
The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data.
Required action
Apply updates per vendor instructions.
NVD description
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.