REDHAT-BUG-1451441: Red Hat JBoss Application Server vulnerability
HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation (jbossmq-httpil.sar, which is enabled by default in Red Hat Jboss Applicatino Server <= Jboss 4.X) does not restrict the classes for which it performs deserialization, which allows remote attackers to execute arbitrary code via crafted serialized data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1451441?
The severity of REDHAT-BUG-1451441 is critical due to potential remote code execution risks.
How do I fix REDHAT-BUG-1451441?
To fix REDHAT-BUG-1451441, it is recommended to upgrade to a version of JBoss Application Server higher than 4.X.
What vulnerability does REDHAT-BUG-1451441 address?
REDHAT-BUG-1451441 addresses a deserialization vulnerability in the JMS over HTTP Invocation Layer of JBossMQ.
Which versions of JBoss Application Server are affected by REDHAT-BUG-1451441?
JBoss Application Server versions up to and including 4.X are affected by REDHAT-BUG-1451441.
What type of attacks can REDHAT-BUG-1451441 facilitate?
REDHAT-BUG-1451441 can facilitate remote code execution attacks by allowing unauthorized deserialization of classes.