CVE-2017-12149

Executive Summary

In Red Hat Enterprise Application Platform 5.2 (JBoss Application Server), the ReadOnlyAccessFilter’s doFilter method fails to restrict deserialization classes, allowing attackers to send crafted serialized payloads that trigger arbitrary code execution. The vulnerability is actively exploited in the wild (CISA KEV).


Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2017-10-04T21:01:00.180 - Last Modified: 2026-10-07T17:58:24.273

[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2021-12-10)

Original Description: In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.

"I am a man of fixed and unbending principles, the first of which is to be flexible at all times."

— Everett Dirksen
Source: NVD