Impact
When Red Hat JBoss Enterprise Application Platform runs with the -secmgr option, the OpenJDK ORB component allows an attacker to provide a Java codebase URL that is honored during object unmarshalling on port 3528. This flaw lets an unauthenticated user load and instantiate arbitrary classes in the server’s JVM before EJB security interceptors execute, potentially giving the attacker full control over the application server.
Affected Systems
The vulnerability affects Red Hat JBoss Enterprise Application Platform versions 7 and 8, as well as the Red Hat JBoss Enterprise Application Platform Expansion Pack. Specific version numbers are not listed, so all installations running these products with the -secmgr option are potentially impacted.
Risk and Exploitability
The vulnerability has a CVSS score of 8.1, indicating a high severity. The EPSS score is not available, but lack of a low EPSS does not reduce the potential impact. The flaw is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a remote attack that connects to the application server’s IIOP port 3528 and supplies a malicious codebase URL. Because the class loading occurs before security checks, an attacker can execute arbitrary code with the privileges of the server process.
OpenCVE Enrichment