CVE-2013-1777
Apache Geronimo JMX Remoting functionality allows remote code execution in 3.x before v3.0.1
EPSS 9.8%
描述
The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not properly implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object.
如何修補 CVE-2013-1777
要修補 CVE-2013-1777,請將受影響套件升級到下列已修補版本。
- Maven/org.apache.geronimo.framework:geronimo-jmx-remoting—升級至 3.0.1 或更新版本
CVE-2013-1777 正在被利用嗎?
中等 — EPSS 為 9.8%,可持續追蹤但非最高優先。
受影響套件(1)
- >= 3.0-beta-1, < 3.0.1