CVE-2013-2165
Summary
| CVE | CVE-2013-2165 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-07-23 11:03:11 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss Enterprise Application Platform through 4.3.0 CP10 and 5.x through 5.2.0, Red Hat JBoss BRMS through 5.3.1, Red Hat JBoss SOA Platform through 4.3.0 CP05 and 5.x through 5.3.1, Red Hat JBoss Portal through 4.3 CP07 and 5.x through 5.2.2, and Red Hat JBoss Operations Network through 2.4.2 and 3.x through 3.1.2 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Jboss Enterprise Application Platform | 4.3.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 4.3.0 | cp10 | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 5.0.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 5.0.1 | All | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 5.1.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 5.1.1 | All | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 5.1.2 | All | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 5.2.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Brms Platform | 5.0.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Brms Platform | 5.0.1 | All | All | All |
| Application | Redhat | Jboss Enterprise Brms Platform | 5.0.2 | All | All | All |
| Application | Redhat | Jboss Enterprise Brms Platform | 5.1.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Brms Platform | 5.2.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Brms Platform | 5.3.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Brms Platform | 5.3.1 | All | All | All |
| Application | Redhat | Jboss Enterprise Portal Platform | 4.3.0 | cp03 | All | All |
| Application | Redhat | Jboss Enterprise Portal Platform | 4.3.0 | cp04 | All | All |
| Application | Redhat | Jboss Enterprise Portal Platform | 4.3.0 | cp05 | All | All |
| Application | Redhat | Jboss Enterprise Portal Platform | 4.3.0 | cp06 | All | All |
| Application | Redhat | Jboss Enterprise Portal Platform | 4.3.0 | cp07 | All | All |
| Application | Redhat | Jboss Enterprise Portal Platform | 5.0.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Portal Platform | 5.0.1 | All | All | All |
| Application | Redhat | Jboss Enterprise Portal Platform | 5.1.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Portal Platform | 5.1.1 | All | All | All |
| Application | Redhat | Jboss Enterprise Portal Platform | 5.2.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Portal Platform | 5.2.1 | All | All | All |
| Application | Redhat | Jboss Enterprise Portal Platform | 5.2.2 | All | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 4.2.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 4.2.0 | cp01 | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 4.2.0 | cp02 | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 4.2.0 | cp03 | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 4.2.0 | cp04 | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 4.2.0 | cp05 | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 4.2.0 | tp02 | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 4.3.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 4.3.0 | cp01 | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 4.3.0 | cp02 | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 4.3.0 | cp03 | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 4.3.0 | cp04 | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 4.3.0 | cp05 | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 5.0.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 5.0.1 | All | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 5.0.2 | All | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 5.1.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 5.1.1 | All | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 5.2.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 5.3.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 5.3.1 | All | All | All |
| Application | Redhat | Jboss Enterprise Web Platform | 5.1.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Web Platform | 5.1.1 | All | All | All |
| Application | Redhat | Jboss Enterprise Web Platform | 5.1.2 | All | All | All |
| Application | Redhat | Jboss Enterprise Web Platform | 5.2.0 | All | All | All |
| Application | Redhat | Jboss Operations Network | 1.0.0 | All | All | All |
| Application | Redhat | Jboss Operations Network | 2.0.0 | All | All | All |
| Application | Redhat | Jboss Operations Network | 2.0.1 | All | All | All |
| Application | Redhat | Jboss Operations Network | 2.1.0 | All | All | All |
| Application | Redhat | Jboss Operations Network | 2.2 | All | All | All |
| Application | Redhat | Jboss Operations Network | 2.3 | All | All | All |
| Application | Redhat | Jboss Operations Network | 2.3.1 | All | All | All |
| Application | Redhat | Jboss Operations Network | 2.4 | All | All | All |
| Application | Redhat | Jboss Operations Network | 2.4.1 | All | All | All |
| Application | Redhat | Jboss Operations Network | 2.4.2 | All | All | All |
| Application | Redhat | Jboss Operations Network | 3.0 | All | All | All |
| Application | Redhat | Jboss Operations Network | 3.0.1 | All | All | All |
| Application | Redhat | Jboss Operations Network | 3.1 | All | All | All |
| Application | Redhat | Jboss Operations Network | 3.1.1 | All | All | All |
| Application | Redhat | Jboss Operations Network | 3.1.2 | All | All | All |
| Application | Redhat | Jboss Web Framework Kit | 1.0.0 | All | All | All |
| Application | Redhat | Jboss Web Framework Kit | 1.1.0 | All | All | All |
| Application | Redhat | Jboss Web Framework Kit | 1.2.0 | All | All | All |
| Application | Redhat | Jboss Web Framework Kit | 2.0.0 | All | All | All |
| Application | Redhat | Jboss Web Framework Kit | 2.1.0 | All | All | All |
| Application | Redhat | Jboss Web Framework Kit | All | All | All | All |
| Application | Redhat | Richfaces | 3.1.0 | All | All | All |
| Application | Redhat | Richfaces | 3.1.1 | All | All | All |
| Application | Redhat | Richfaces | 3.1.2 | All | All | All |
| Application | Redhat | Richfaces | 3.1.3 | All | All | All |
| Application | Redhat | Richfaces | 3.1.4 | All | All | All |
| Application | Redhat | Richfaces | 3.1.5 | All | All | All |
| Application | Redhat | Richfaces | 3.1.6 | All | All | All |
| Application | Redhat | Richfaces | 3.2.0 | All | All | All |
| Application | Redhat | Richfaces | 3.2.0 | sr1 | All | All |
| Application | Redhat | Richfaces | 3.2.1 | All | All | All |
| Application | Redhat | Richfaces | 3.2.2 | All | All | All |
| Application | Redhat | Richfaces | 3.3.0 | All | All | All |
| Application | Redhat | Richfaces | 3.3.1 | All | All | All |
| Application | Redhat | Richfaces | 3.3.2 | All | All | All |
| Application | Redhat | Richfaces | 3.3.2 | sr1 | All | All |
| Application | Redhat | Richfaces | 3.3.3 | All | All | All |
| Application | Redhat | Richfaces | 4.0.0 | All | All | All |
| Application | Redhat | Richfaces | 4.1.0 | All | All | All |
| Application | Redhat | Richfaces | 4.2.0 | All | All | All |
| Application | Redhat | Richfaces | 4.2.1 | All | All | All |
| Application | Redhat | Richfaces | 4.2.2 | All | All | All |
| Application | Redhat | Richfaces | 4.2.3 | All | All | All |
| Application | Redhat | Richfaces | 4.3.0 | All | All | All |
| Application | Redhat | Richfaces | 4.3.1 | All | All | All |
| Application | Redhat | Richfaces | 4.5.0 | alpha1 | All | All |
| Application | Redhat | Richfaces | 5.0.0 | alpha1 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Vendor Advisory |
| JVN#38787103: JBoss RichFaces vulnerable to remote code execution | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | Third Party Advisory, VDB Entry |
| access.redhat.com | CVE-2013-2165 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Vendor Advisory |
| rhn.redhat.com/errata/RHSA-2013-1045.html | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Vendor Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Vendor Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Vendor Advisory |
| 973570 – (CVE-2013-2165) CVE-2013-2165 JBoss RichFaces: Remote code execution due to insecure deserialization | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Vendor Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Vendor Advisory |
| jvndb.jvn.jp/jvndb/JVNDB-2013-000072 | af854a3a-2127-422b-91ae-364da2661108 | jvndb.jvn.jp | Third Party Advisory, VDB Entry |
| Full Disclosure: RichFaces exploitation toolkit | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| Richsploit RichFaces Exploitation Toolkit ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | |
| Red Hat Customer Portal - Access to 24x7 support and knowledge | MITRE | access.redhat.com | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| Red Hat Customer Portal - Access to 24x7 support and knowledge | MITRE | access.redhat.com | |
| Red Hat Customer Portal - Access to 24x7 support and knowledge | MITRE | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.