CVE-2013-1777
Summary
| CVE | CVE-2013-1777 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-07-11 22:55:00 UTC |
| Updated | 2014-04-01 06:19:00 UTC |
| Description | The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not properly implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object. |
Risk And Classification
Problem Types: CWE-94
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Geronimo | 3.0 | All | All | All |
| Application | Apache | Geronimo | 3.0 | beta1 | All | All |
| Application | Apache | Geronimo | 3.0 | m1 | All | All |
| Application | Apache | Geronimo | 3.0 | All | All | All |
| Application | Apache | Geronimo | 3.0 | beta1 | All | All |
| Application | Apache | Geronimo | 3.0 | m1 | All | All |
| Application | Ibm | Websphere Application Server | 3.0.0.3 | - | community | All |
| Application | Ibm | Websphere Application Server | 3.0.0.3 | - | community | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [GERONIMO-6477] Misconfigured RMI classloader - ASF JIRA | CONFIRM | issues.apache.org | |
| Apache Geronimo : 3.0.x Security Report | CONFIRM | geronimo.apache.org | Vendor Advisory |
| NEOHAPSIS - Peace of Mind Through Integrity and Insight | BUGTRAQ | archives.neohapsis.com | |
| IBM Security Bulletin: WebSphere Application Server Community Edition 3.0.0.3 RMI classloader exposure - United States | CONFIRM | www-01.ibm.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.