{
  "id": "CVE-2017-12149",
  "url": "https://spydr.io/cve/CVE-2017-12149",
  "published": "2017-10-04T21:01:00.180Z",
  "modified": "2026-10-07T17:58:24.273Z",
  "score": 9.8,
  "severity": "critical",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
  "score_source": "NVD",
  "epss": 0.90713,
  "epss_percentile": 0.99803,
  "exploited": true,
  "kev": {
    "added": "2021-12-10",
    "due": "2022-06-10",
    "action": "Apply updates per vendor instructions.",
    "ransomware": "Known",
    "name": "Red Hat JBoss Application Server Remote Code Execution Vulnerability",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2017-12149"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "Red Hat, Inc."
  ],
  "products": [
    "Red Hat, Inc. jbossas"
  ],
  "cwes": [
    "CWE-502"
  ],
  "description": "In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 9.8,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/100591",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2018:1607",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2018:1608",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1486220",
      "tags": [
        "Issue Tracking"
      ]
    },
    {
      "url": "https://github.com/gottburgm/Exploits/tree/master/CVE-2017-12149",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12149",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2017-12149",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
