10

CVE-2013-1777

The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not properly implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Geronimo Version 3.0
Apache ≫ Geronimo Version 3.0 Update beta1
Apache ≫ Geronimo Version 3.0 Update m1
Ibm ≫ Websphere Application Server Version 3.0.0.3 Update - Edition community
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.81% 0.949
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

http://archives.neohapsis.com/archives/bugtraq/2013-07/0008.html
http://geronimo.apache.org/30x-security-report.html
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21643282
Patch
Vendor Advisory
https://issues.apache.org/jira/browse/GERONIMO-6477