Description
ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss Enterprise Application Platform through 4.3.0 CP10 and 5.x through 5.2.0, Red Hat JBoss BRMS through 5.3.1, Red Hat JBoss SOA Platform through 4.3.0 CP05 and 5.x through 5.3.1, Red Hat JBoss Portal through 4.3 CP07 and 5.x through 5.2.2, and Red Hat JBoss Operations Network through 2.4.2 and 3.x through 3.1.2 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4344-frcp-j22q | Remote code execution due to insecure deserialization |
References
History
No history.
Subscriptions
Redhat
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Brms Platform
Subscribe
Jboss Enterprise Portal Platform
Subscribe
Jboss Enterprise Soa Platform
Subscribe
Jboss Enterprise Web Framework
Subscribe
Jboss Enterprise Web Platform
Subscribe
Jboss Operations Network
Subscribe
Jboss Web Framework Kit
Subscribe
Richfaces
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T15:27:41.075Z
Reserved: 2013-02-19T00:00:00.000Z
Link: CVE-2013-2165
No data.
Status : Deferred
Published: 2013-07-23T11:03:11.980
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-2165
OpenCVE Enrichment
No data.
Github GHSA