CVE-2017-5641
Last modified
CVE-2017-5641 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object deserialization by default. During the deserialization process code is executed that for several known types has undesired side-effects. EPSS estimates a 21.27% chance of exploitation in the next 30 days.
Description
Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object deserialization by default. During the deserialization process code is executed that for several known types has undesired side-effects. Other, unknown types may also exhibit such behaviors. One vector in the Java standard library exists that allows an attacker to trigger possibly further exploitable Java deserialization of untrusted data. Other known vectors in third party libraries can be used to trigger remote code execution.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Flex Blazeds | <= 4.7.2 |
| Hp | Xp Command View Advanced Edition | < 8.5.3-00 |
References
- http://www.securityfocus.com/bid/97383Broken Link
- http://www.securitytracker.com/id/1038273Broken Link
- https://issues.apache.org/jira/browse/FLEX-35290Issue Tracking, Vendor Advisory
- https://www.kb.cert.org/vuls/id/307983Third Party Advisory, US Government Resource
- https://www.zerodayinitiative.com/advisories/ZDI-22-506/Third Party Advisory, VDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-22-507/Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/97383Broken Link
- http://www.securitytracker.com/id/1038273Broken Link
- https://issues.apache.org/jira/browse/FLEX-35290Issue Tracking, Vendor Advisory
- https://www.kb.cert.org/vuls/id/307983Third Party Advisory, US Government Resource
- https://www.zerodayinitiative.com/advisories/ZDI-22-506/Third Party Advisory, VDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-22-507/Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-5641?
How severe is CVE-2017-5641?
How do I fix CVE-2017-5641?
Are you affected by CVE-2017-5641?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
