ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss Enterprise Application Platform through 4.3.0 CP10 and 5.x through 5.2.0, Red Hat JBoss BRMS through 5.3.1, Red Hat JBoss SOA Platform through 4.3.0 CP05 and 5.x through 5.3.1, Red Hat JBoss Portal through 4.3 CP07 and 5.x through 5.2.2, and Red Hat JBoss Operations Network through 2.4.2 and 3.x through 3.1.2 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Redhat
Subscribe
|
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Brms Platform
Subscribe
Jboss Enterprise Portal Platform
Subscribe
Jboss Enterprise Soa Platform
Subscribe
Jboss Enterprise Web Framework
Subscribe
Jboss Enterprise Web Platform
Subscribe
Jboss Operations Network
Subscribe
Jboss Web Framework Kit
Subscribe
Richfaces
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4344-frcp-j22q | Remote code execution due to insecure deserialization |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T15:27:41.075Z
Reserved: 2013-02-19T00:00:00
Link: CVE-2013-2165
No data.
Status : Deferred
Published: 2013-07-23T11:03:11.980
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-2165
OpenCVE Enrichment
No data.
Github GHSA