id: CVE-2017-7504 info: name: JBossMQ HTTP Invocation Layer (HTTPServerILServlet) - Unauthenticated Java Deserialization author: Jayachandran severity: critical description: | The JMS over HTTP Invocation Layer in JBossMQ, as implemented in HTTPServerILServlet.java in JBoss Application Server (AS) 4.x and earlier, does not properly restrict the classes that can be deserialized from the raw POST body. This allows remote attackers to execute arbitrary code or cause a denial of service (application crash or other impacts) via crafted serialized objects, due to insecure Java object deserialization. remediation: | Upgrade JBoss AS to a supported EAP version, or remove the jbossmq-httpil.sar deployment if JMS-over-HTTP is not required. reference: - https://github.com/vulhub/vulhub/blob/master/jboss/CVE-2017-7504/README.md - https://nvd.nist.gov/vuln/detail/CVE-2017-7504 classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2017-7504 cwe-id: CWE-502 epss-score: 0.41019 epss-percentile: 0.98573 cpe: cpe:2.3:a:redhat:jboss_application_server:4.0.5:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: redhat product: jboss_application_server shodan-query: http.title:"JBoss" fofa-query: app="JBoss" tags: cve,cve2017,redhat,jboss,jbossmq,deserialization,rce,vkev http: - method: POST path: - "{{BaseURL}}/jbossmq-httpil/HTTPServerILServlet" headers: Content-Type: application/octet-stream body: "{{base64_decode(\"rO0ABXQABWhlbGxv\")}}" matchers-condition: and matchers: - type: word part: body words: - "cannot be cast to org.jboss.mq.il.http.HTTPILRequest" - "java.lang.ClassCastException" condition: and - type: status status: - 200 # digest: 490a004630440220735892031c4a68251c2127d714692112655606045d5f89f8bf8dae57456b87010220110caa62bb6c6c42266f3107961ddcea68e7dd18052f58ebdbaab28b789c22ce:922c64590222798bb761d5b6d8e72950