CVE-2017-7504: Red Hat JBoss Enterprise Application Platform

Critical severity, CVSS 9.8. EPSS: 38.9% chance of exploitation in the next 30 days.

HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Server <= Jboss 4.X does not restrict the classes for which it performs deserialization, which allows remote attackers to execute arbitrary code via crafted serialized data.

Affected products

  • Red Hat JBoss Enterprise Application Platform: up to and including 4.0

Published 2017-05-19. Last modified 2026-06-17.