7.5

CVE-2013-2165

ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss Enterprise Application Platform through 4.3.0 CP10 and 5.x through 5.2.0, Red Hat JBoss BRMS through 5.3.1, Red Hat JBoss SOA Platform through 4.3.0 CP05 and 5.x through 5.3.1, Red Hat JBoss Portal through 4.3 CP07 and 5.x through 5.2.2, and Red Hat JBoss Operations Network through 2.4.2 and 3.x through 3.1.2 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data.

Data is provided by the National Vulnerability Database (NVD)
RedhatJboss Enterprise Application Platform Version4.3.0 Updatecp10
RedhatJboss Enterprise Portal Platform Version4.3.0 Updatecp03
RedhatJboss Enterprise Portal Platform Version4.3.0 Updatecp04
RedhatJboss Enterprise Portal Platform Version4.3.0 Updatecp05
RedhatJboss Enterprise Portal Platform Version4.3.0 Updatecp06
RedhatJboss Enterprise Portal Platform Version4.3.0 Updatecp07
RedhatJboss Enterprise Soa Platform Version4.2.0 Updatecp01
RedhatJboss Enterprise Soa Platform Version4.2.0 Updatecp02
RedhatJboss Enterprise Soa Platform Version4.2.0 Updatecp03
RedhatJboss Enterprise Soa Platform Version4.2.0 Updatecp04
RedhatJboss Enterprise Soa Platform Version4.2.0 Updatecp05
RedhatJboss Enterprise Soa Platform Version4.2.0 Updatetp02
RedhatJboss Enterprise Soa Platform Version4.3.0 Updatecp01
RedhatJboss Enterprise Soa Platform Version4.3.0 Updatecp02
RedhatJboss Enterprise Soa Platform Version4.3.0 Updatecp03
RedhatJboss Enterprise Soa Platform Version4.3.0 Updatecp04
RedhatJboss Enterprise Soa Platform Version4.3.0 Updatecp05
RedhatJboss Operations Network Version1.0.0
RedhatJboss Operations Network Version2.0.0
RedhatJboss Operations Network Version2.0.1
RedhatJboss Operations Network Version2.1.0
RedhatJboss Operations Network Version2.3.1
RedhatJboss Operations Network Version2.4.1
RedhatJboss Operations Network Version2.4.2
RedhatJboss Operations Network Version3.0.1
RedhatJboss Operations Network Version3.1.1
RedhatJboss Operations Network Version3.1.2
RedhatJboss Web Framework Kit Version <= 2.2.0
RedhatJboss Web Framework Kit Version1.0.0
RedhatJboss Web Framework Kit Version1.1.0
RedhatJboss Web Framework Kit Version1.2.0
RedhatJboss Web Framework Kit Version2.0.0
RedhatJboss Web Framework Kit Version2.1.0
RedhatRichfaces Version3.1.0
RedhatRichfaces Version3.1.1
RedhatRichfaces Version3.1.2
RedhatRichfaces Version3.1.3
RedhatRichfaces Version3.1.4
RedhatRichfaces Version3.1.5
RedhatRichfaces Version3.1.6
RedhatRichfaces Version3.2.0
RedhatRichfaces Version3.2.0 Updatesr1
RedhatRichfaces Version3.2.1
RedhatRichfaces Version3.2.2
RedhatRichfaces Version3.3.0
RedhatRichfaces Version3.3.1
RedhatRichfaces Version3.3.2
RedhatRichfaces Version3.3.2 Updatesr1
RedhatRichfaces Version3.3.3
RedhatRichfaces Version4.0.0
RedhatRichfaces Version4.1.0
RedhatRichfaces Version4.2.0
RedhatRichfaces Version4.2.1
RedhatRichfaces Version4.2.2
RedhatRichfaces Version4.2.3
RedhatRichfaces Version4.3.0
RedhatRichfaces Version4.3.1
RedhatRichfaces Version4.5.0 Updatealpha1
RedhatRichfaces Version5.0.0 Updatealpha1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 25.71% 0.96
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P