The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not properly implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2013-07-11T22:00:00
Updated: 2024-08-06T15:13:32.883Z
Reserved: 2013-02-19T00:00:00
Link: CVE-2013-1777
Vulnrichment
No data.
NVD
Status : Modified
Published: 2013-07-11T22:55:00.883
Modified: 2024-11-21T01:50:22.143
Link: CVE-2013-1777
Redhat