CVE-2017-15708
Summary
| CVE | CVE-2017-15708 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-12-11 15:29:00 UTC |
| Updated | 2023-11-07 02:40:00 UTC |
| Description | In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) allows remote code execution attacks that can be performed by injecting specially crafted serialized objects. And the presence of Apache Commons Collections 3.2.1 (commons-collections-3.2.1.jar) or previous versions in Synapse distribution makes this exploitable. To mitigate the issue, we need to limit RMI access to trusted users only. Further upgrading to 3.0.1 version will eliminate the risk of having said Commons Collection version. In Synapse 3.0.1, Commons Collection has been updated to 3.2.2 version. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Apache Commons Collections: Remote code execution (GLSA 202107-37) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Oracle Critical Patch Update Advisory - July 2020 |
MISC |
www.oracle.com |
|
| Multiple Apache Products CVE-2017-15708 Remote Code Execution Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| [doris-commits] 20210402 [GitHub] [incubator-doris] zh0122 opened a new pull request #5595: [FE][Fix]Update commons-collections to fix a security issue |
|
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| Oracle Critical Patch Update Advisory - January 2020 |
MISC |
www.oracle.com |
|
| Pony Mail! |
MLIST |
lists.apache.org |
Issue Tracking, Mailing List, Vendor Advisory |
| Pony Mail! |
|
lists.apache.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710031 Gentoo Linux Apache Commons Collections Remote code execution (GLSA 202107-37)
- 92029 Microsoft SQL Server Multiple Vulnerabilities
- 982335 Java (maven) Security Update for org.apache.synapse:synapse-core (GHSA-p694-23q3-rvrc)