10
CVSSv2

CVE-2013-1777

Published: 11/07/2013 Updated: 01/04/2014
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The JMX Remoting functionality in Apache Geronimo 3.x prior to 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not properly implement the RMI classloader, which allows remote malicious users to execute arbitrary code by using the JMX connector to send a crafted serialized object.

Vulnerable Product Search on Vulmon Subscribe to Product

apache geronimo 3.0

ibm websphere application server 3.0.0.3

Vendor Advisories

The JMX Remoting functionality in Apache Geronimo 3x before 301, as used in IBM WebSphere Application Server (WAS) Community Edition 3003 and other products, does not properly implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object ...