Lucene search

K
nvd[email protected]NVD:CVE-2013-2165
HistoryJul 23, 2013 - 11:03 a.m.

CVE-2013-2165

2013-07-2311:03:11
CWE-264
web.nvd.nist.gov
1

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

AI Score

Confidence

High

0.1 Low

EPSS

Percentile

94.9%

ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss Enterprise Application Platform through 4.3.0 CP10 and 5.x through 5.2.0, Red Hat JBoss BRMS through 5.3.1, Red Hat JBoss SOA Platform through 4.3.0 CP05 and 5.x through 5.3.1, Red Hat JBoss Portal through 4.3 CP07 and 5.x through 5.2.2, and Red Hat JBoss Operations Network through 2.4.2 and 3.x through 3.1.2 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data.

Affected configurations

NVD
Node
redhatjboss_enterprise_application_platformMatch4.3.0
OR
redhatjboss_enterprise_application_platformMatch4.3.0cp10
OR
redhatjboss_enterprise_application_platformMatch5.0.0
OR
redhatjboss_enterprise_application_platformMatch5.0.1
OR
redhatjboss_enterprise_application_platformMatch5.1.0
OR
redhatjboss_enterprise_application_platformMatch5.1.1
OR
redhatjboss_enterprise_application_platformMatch5.1.2
OR
redhatjboss_enterprise_application_platformMatch5.2.0
OR
redhatjboss_enterprise_brms_platformMatch5.0.0
OR
redhatjboss_enterprise_brms_platformMatch5.0.1
OR
redhatjboss_enterprise_brms_platformMatch5.0.2
OR
redhatjboss_enterprise_brms_platformMatch5.1.0
OR
redhatjboss_enterprise_brms_platformMatch5.2.0
OR
redhatjboss_enterprise_brms_platformMatch5.3.0
OR
redhatjboss_enterprise_brms_platformMatch5.3.1
OR
redhatjboss_enterprise_portal_platformMatch4.3.0cp03
OR
redhatjboss_enterprise_portal_platformMatch4.3.0cp04
OR
redhatjboss_enterprise_portal_platformMatch4.3.0cp05
OR
redhatjboss_enterprise_portal_platformMatch4.3.0cp06
OR
redhatjboss_enterprise_portal_platformMatch4.3.0cp07
OR
redhatjboss_enterprise_portal_platformMatch5.0.0
OR
redhatjboss_enterprise_portal_platformMatch5.0.1
OR
redhatjboss_enterprise_portal_platformMatch5.1.0
OR
redhatjboss_enterprise_portal_platformMatch5.1.1
OR
redhatjboss_enterprise_portal_platformMatch5.2.0
OR
redhatjboss_enterprise_portal_platformMatch5.2.1
OR
redhatjboss_enterprise_portal_platformMatch5.2.2
OR
redhatjboss_enterprise_soa_platformMatch4.2.0
OR
redhatjboss_enterprise_soa_platformMatch4.2.0cp01
OR
redhatjboss_enterprise_soa_platformMatch4.2.0cp02
OR
redhatjboss_enterprise_soa_platformMatch4.2.0cp03
OR
redhatjboss_enterprise_soa_platformMatch4.2.0cp04
OR
redhatjboss_enterprise_soa_platformMatch4.2.0cp05
OR
redhatjboss_enterprise_soa_platformMatch4.2.0tp02
OR
redhatjboss_enterprise_soa_platformMatch4.3.0
OR
redhatjboss_enterprise_soa_platformMatch4.3.0cp01
OR
redhatjboss_enterprise_soa_platformMatch4.3.0cp02
OR
redhatjboss_enterprise_soa_platformMatch4.3.0cp03
OR
redhatjboss_enterprise_soa_platformMatch4.3.0cp04
OR
redhatjboss_enterprise_soa_platformMatch4.3.0cp05
OR
redhatjboss_enterprise_soa_platformMatch5.0.0
OR
redhatjboss_enterprise_soa_platformMatch5.0.1
OR
redhatjboss_enterprise_soa_platformMatch5.0.2
OR
redhatjboss_enterprise_soa_platformMatch5.1.0
OR
redhatjboss_enterprise_soa_platformMatch5.1.1
OR
redhatjboss_enterprise_soa_platformMatch5.2.0
OR
redhatjboss_enterprise_soa_platformMatch5.3.0
OR
redhatjboss_enterprise_soa_platformMatch5.3.1
OR
redhatjboss_enterprise_web_platformMatch5.1.0
OR
redhatjboss_enterprise_web_platformMatch5.1.1
OR
redhatjboss_enterprise_web_platformMatch5.1.2
OR
redhatjboss_enterprise_web_platformMatch5.2.0
OR
redhatjboss_operations_networkMatch1.0.0
OR
redhatjboss_operations_networkMatch2.0.0
OR
redhatjboss_operations_networkMatch2.0.1
OR
redhatjboss_operations_networkMatch2.1.0
OR
redhatjboss_operations_networkMatch2.2
OR
redhatjboss_operations_networkMatch2.3
OR
redhatjboss_operations_networkMatch2.3.1
OR
redhatjboss_operations_networkMatch2.4
OR
redhatjboss_operations_networkMatch2.4.1
OR
redhatjboss_operations_networkMatch2.4.2
OR
redhatjboss_operations_networkMatch3.0
OR
redhatjboss_operations_networkMatch3.0.1
OR
redhatjboss_operations_networkMatch3.1
OR
redhatjboss_operations_networkMatch3.1.1
OR
redhatjboss_operations_networkMatch3.1.2
OR
redhatjboss_web_framework_kitRange≀2.2.0
OR
redhatjboss_web_framework_kitMatch1.0.0
OR
redhatjboss_web_framework_kitMatch1.1.0
OR
redhatjboss_web_framework_kitMatch1.2.0
OR
redhatjboss_web_framework_kitMatch2.0.0
OR
redhatjboss_web_framework_kitMatch2.1.0
OR
redhatrichfacesMatch3.1.0
OR
redhatrichfacesMatch3.1.1
OR
redhatrichfacesMatch3.1.2
OR
redhatrichfacesMatch3.1.3
OR
redhatrichfacesMatch3.1.4
OR
redhatrichfacesMatch3.1.5
OR
redhatrichfacesMatch3.1.6
OR
redhatrichfacesMatch3.2.0
OR
redhatrichfacesMatch3.2.0sr1
OR
redhatrichfacesMatch3.2.1
OR
redhatrichfacesMatch3.2.2
OR
redhatrichfacesMatch3.3.0
OR
redhatrichfacesMatch3.3.1
OR
redhatrichfacesMatch3.3.2
OR
redhatrichfacesMatch3.3.2sr1
OR
redhatrichfacesMatch3.3.3
OR
redhatrichfacesMatch4.0.0
OR
redhatrichfacesMatch4.1.0
OR
redhatrichfacesMatch4.2.0
OR
redhatrichfacesMatch4.2.1
OR
redhatrichfacesMatch4.2.2
OR
redhatrichfacesMatch4.2.3
OR
redhatrichfacesMatch4.3.0
OR
redhatrichfacesMatch4.3.1
OR
redhatrichfacesMatch4.5.0alpha1
OR
redhatrichfacesMatch5.0.0alpha1

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

AI Score

Confidence

High

0.1 Low

EPSS

Percentile

94.9%