[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2010-3708Date: (C)2010-12-30   (M)2023-12-22


The serialization implementation in JBoss Drools in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 and JBoss Enterprise SOA Platform 4.2 and 4.3 supports the embedding of class files, which allows remote attackers to execute arbitrary code via a crafted static initializer.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1024813
RHSA-2010:0937
RHSA-2010:0938
RHSA-2010:0939
RHSA-2010:0940
https://bugzilla.redhat.com/show_bug.cgi?id=633859
https://issues.jboss.org/browse/SOA-2319

CPE    13
cpe:/a:redhat:jboss_enterprise_soa_platform:4.2.0:cp03
cpe:/a:redhat:jboss_enterprise_soa_platform:4.2.0:cp02
cpe:/a:redhat:jboss_enterprise_soa_platform:4.2.0:cp05
cpe:/a:redhat:jboss_enterprise_soa_platform:4.3.0:cp03
...
CWE    1
CWE-20

© SecPod Technologies