August 10, 2026

CVE Watchtower


← Back to CVE List

CVE-2017-12149NVD

Vulnerability Summary

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.
Severity Level
CRITICAL(9.8)
Published Date
Oct 4, 2017
Last Modified
Apr 21, 2026
Exploitation Status
ACTIVE
EPSS Score (30-Day)
94.29%Probability
Root Weakness (CWE)
Refer to the official MITRE database for detailed architectural specifications regarding this weakness.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh