CVE-2017-7504Disclosure(redhat / jboss_enterprise_application_platform)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Server <= Jboss 4.X does not restrict the classes for which it performs deserialization, which allows remote attackers to execute arbitrary code via crafted serialized data.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jboss_enterprise_application_platform

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
jboss_enterprise_application_platform

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-25: 1Technical Details · 2026-08-25: 108-25
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2017-7504 - critical 🚨 JBossMQ HTTP Invocation Layer (HTTPServerILServlet) - Unauthenticated Java Deserialization &gt; The JMS over HTTP Invocation Layer in JBossMQ, as implemented in HTTPServerILServlet.... 👾 https://cloud.projectdiscovery.io/library/CVE-2017-7504 @pdn...

    Post summary

    The tweet announces CVE-2017-7504, a critical unauthenticated Java deserialization flaw in JBossMQ's HTTPServerILServlet, linking to a ProjectDiscovery library page for more information. No PoC, exploit code, or patch details are provided.

    01071672
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appredhatjboss_enterprise_application_platform---

Explore more