1. Symantec-Broadcom-Horizontal/
  2. Security Response/
  3. Attack Signatures/
  4. Attack: JBoss Commons-Collections JAVA Library Deserialization RCE

Attack: JBoss Commons-Collections JAVA Library Deserialization RCE

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

This signature detects attempts to execute arbitrary code on vulnerable installations of JBoss Application Server. Authentication is not required to exploit this vulnerability.

Additional Information

JBoss Application Server is prone to a remote vulnerability due to deserialization of untrusted inputs, allowing attackers to instantiate arbitrary Java objects leading to remote code execution.

Affected

  • Various JBoss Application Server versions.
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube