VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-3708
jboss_enterprise_application_platform, jboss_enterprise_soa_platform: The serialization implementation in JBoss Drools in...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-3708

Original

The serialization implementation in JBoss Drools in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 and JBoss Enterprise SOA Platform 4.2 and 4.3 supports the embedding of class files, which allows remote attackers to execute arbitrary code via a crafted static initializer.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-12-30
Source Information Category:
Advisory, Alert
Last Updated:
2010-12-30




Affected Product Tags
cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0
cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0:cp01
cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0:cp02
cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0:cp03
cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0:cp04
cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0:cp05
cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0:cp06
cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0:cp07
cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0:cp08
cpe:/a:redhat:jboss_enterprise_soa_platform:4.2.0
cpe:/a:redhat:jboss_enterprise_soa_platform:4.2.0:cp01
cpe:/a:redhat:jboss_enterprise_soa_platform:4.2.0:cp02
cpe:/a:redhat:jboss_enterprise_soa_platform:4.2.0:cp03
cpe:/a:redhat:jboss_enterprise_soa_platform:4.2.0:cp04
cpe:/a:redhat:jboss_enterprise_soa_platform:4.2.0:cp05
cpe:/a:redhat:jboss_enterprise_soa_platform:4.2.0:tp02
cpe:/a:redhat:jboss_enterprise_soa_platform:4.3.0
cpe:/a:redhat:jboss_enterprise_soa_platform:4.3.0:cp01
cpe:/a:redhat:jboss_enterprise_soa_platform:4.3.0:cp02
cpe:/a:redhat:jboss_enterprise_soa_platform:4.3.0:cp03
cpe:/a:redhat:jboss_enterprise_soa_platform:4.3.0:cp04
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
X Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
Medium [?]
X Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Availability Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

Alternatives




References
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=633859




MISC https://issues.jboss.org/browse/SOA-2319




REDHAT RHSA-2010:0940




REDHAT RHSA-2010:0939




REDHAT RHSA-2010:0938




REDHAT RHSA-2010:0937




SECTRACK 1024813




Vulnerability Type Input Validation (CWE-20)





Copyright © 2010 JPCERT/CC All Rights Reserved.