EXPOSURES › CVE-2017-12149
CVE-2017-12149
CRITICAL ⌖ ON CISA KEV · EXPLOITEDA vulnerability in Red Hat JBoss Application Server allowed attackers to execute arbitrary code remotely, linked to ransomware activity.
JBoss Application Server versions shipped with Red Hat Enterprise Application Platform 5.2 contained a remote code execution vulnerability exploitable via crafted serialized data, which has been actively exploited in the wild and linked to ransomware. DIB organizations using this product are at risk of code execution and data compromise, potentially impacting CMMC compliance. Immediate patching and vulnerability scanning are required.
Shame score — The vulnerability's exploitation in ransomware attacks and the availability of a fix demonstrate a significant failure in patching and security practices.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data.
| PRODUCT | STATUS |
|---|---|
| Red Hat OpenShift Service on AWS (ROSA) Red Hat |
In Process |