CVE-2012-0874
published 2013-02-05CVE-2012-0874: The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before…
PriorityP180medium6.8CVSS 2.0
AVNACMAuNCPIPAP
ITWEXPLOITVulnCheck KEVRansomware
Exploited in the wild
EPSS
15.56%
96.5th percentile
The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 do not require authentication by default in certain profiles, which might allow remote attackers to invoke MBean methods and execute arbitrary code via unspecified vectors. NOTE: this issue can only be exploited when the interceptor is not properly configured with a "second layer of authentication," or when used in conjunction with other vulnerabilities that bypass this second layer.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | procurve_manager | — | — |
| hp | procurve_manager | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_brms_platform | <= 5.3.0 | — |
| redhat | jboss_enterprise_web_platform | — | — |
Detection & IOCsextracted from sources · hover to see the quote
otherContentType: application/x-java-serialized-object; class=org.jboss.invocation.MarshalledInvocation↗
- →The interceptor that blocks exploitation by default is declared in jboss-as/server/$PROFILE/deploy/jmx-invoker-service.xml; absence or misconfiguration of this file leaves the system exploitable. ↗
- →SamSam ransomware actors exploited CVE-2012-0874 in the wild; hunt for JBoss invoker servlet access in web logs as a precursor to ransomware deployment. ↗
- ·The vulnerability is only directly exploitable when the security interceptor is misconfigured or disabled; a properly configured second layer of authentication in jmx-invoker-service.xml prevents exploitation. ↗
- ·All supported Red Hat JBoss products apply authentication to these servlet interfaces by default and are not affected; only older unsupported community releases of JBoss AS 4.x and 5.x are exposed by default. ↗
- ·JBoss AS (WildFly) 7.x community releases are also not affected by this issue. ↗
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck6.8MEDIUM
vendor_redhat6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JBoss invoker servlets do not require authentication
vendor_redhat·2013-01-24·CVSS 6.8
CVE-2012-0874 [MEDIUM] JBoss invoker servlets do not require authentication
JBoss invoker servlets do not require authentication
The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 do not require authentication by default in certain profiles, which might allow remote attackers to invoke MBean methods and execute arbitrary code via unspecified vectors. NOTE: this issue can only be exploited when the interceptor is not properly configured with a "second layer of authentication," or when used in conjunction with other vulnerabilities that bypass this second layer.
Package: Security (Red Hat JBoss BRMS 5) - Not affected
Package: Requirements (Red Hat JBoss Portal 4) - Affected
Package: Requirem
GHSA
GHSA-mm58-72w4-25hp: HP ProCurve Manager (PCM) 3
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2013-4810 [HIGH] CWE-94 GHSA-mm58-72w4-25hp: HP ProCurve Manager (PCM) 3
HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet, aka ZDI-CAN-1760. NOTE: this is probably a duplicate of CVE-2007-1036, CVE-2010-0738, and/or CVE-2012-0874.
GHSA
GHSA-cjrh-9rp2-h6f2: The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5
ghsa_unreviewed·2022-05-17
CVE-2012-0874 [MEDIUM] CWE-287 GHSA-cjrh-9rp2-h6f2: The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5
The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 do not require authentication by default in certain profiles, which might allow remote attackers to invoke MBean methods and execute arbitrary code via unspecified vectors. NOTE: this issue can only be exploited when the interceptor is not properly configured with a "second layer of authentication," or when used in conjunction with other vulnerabilities that bypass this second layer.
VulnCheck
Red Hat JBoss Application Server Improper Authentication
vulncheck·2012·CVSS 6.8
CVE-2012-0874 [MEDIUM] Red Hat JBoss Application Server Improper Authentication
Red Hat JBoss Application Server Improper Authentication
The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 do not require authentication by default in certain profiles, which might allow remote attackers to invoke MBean methods and execute arbitrary code via unspecified vectors. NOTE: this issue can only be exploited when the interceptor is not properly configured with a "second layer of authentication," or when used in conjunction with other vulnerabilities that bypass this second layer.
Affected: Red Hat JBoss Application Server
Required Action: Apply remediations or mitigations per vendor instructions or discont
No detection rules found.
Bugzilla
CVE-2015-7501 apache-commons-collections: InvokerTransformer code execution during deserialisation
bugzilla·2015-11-09·CVSS 6.8
CVE-2015-7501 [MEDIUM] CVE-2015-7501 apache-commons-collections: InvokerTransformer code execution during deserialisation
CVE-2015-7501 apache-commons-collections: InvokerTransformer code execution during deserialisation
It was found that a flaw in commons-collection library allowed remote code execution wherever deserialization occurs. While JBoss doesnt expose the JMXInvokerServlet by default, other interfaces where deserialization occur might be vulnerable.
Note: classes directly referenced by this flaw:
InvokerTransformer, InstantiateFactory, and InstantiateTransformer
External References:
http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/
https://access.redhat.com/solutions/2045023
Discussion:
This was addressed back in 2012:
https://access.redhat.com/security/cve/CVE-2012-0874
While we have the JMXInvoke
Bugzilla
CVE-2013-4810 HP ProCurve Manager (PCM): invoker servlets do not require authentication
bugzilla·2013-11-18·CVSS 6.8
CVE-2013-4810 [MEDIUM] CVE-2013-4810 HP ProCurve Manager (PCM): invoker servlets do not require authentication
CVE-2013-4810 HP ProCurve Manager (PCM): invoker servlets do not require authentication
The HP ProCurve Manager (PCM) was found to expose unauthenticated JMXInvokerServlet and EJBInvokerServlet interfaces. A remote attacker could exploit this flaw to invoke MBean methods and run arbitrary code in the context of the user running the PCM server.
Discussion:
Statement:
CVE-2013-4810 refers to the exposure of unauthenticated JMXInvokerServlet and EJBInvokerServlet interfaces on HP ProCurve Manager (PCM). These servlets are also, however, exposed without authentication on older, unsupported community releases of JBoss AS (WildFly) 4.x and 5.x.
All supported Red Hat JBoss products that include the JMXInvokerServlet and EJBInvokerServlet interfaces apply authentication by default and are not
Bugzilla
CVE-2012-3173 mysql: unspecified DoS vulnerability related to InnoDB Plugin (CPU Oct 2012)
bugzilla·2012-10-17·CVSS 4.0
CVE-2012-3173 [MEDIUM] CVE-2012-3173 mysql: unspecified DoS vulnerability related to InnoDB Plugin (CPU Oct 2012)
CVE-2012-3173 mysql: unspecified DoS vulnerability related to InnoDB Plugin (CPU Oct 2012)
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-3173 to
the following vulnerability:
Name: CVE-2012-3173
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3173
Assigned: 20120606
Reference: http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html
Unspecified vulnerability in the MySQL Server component in Oracle
MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote
authenticated users to affect availability via unknown vectors related
to InnoDB Plugin.
Discussion:
InnoDB plugin was first enabled in MySQL packages in Red Hat Enterprise Linux 6 via Red Hat Enterprise Linux 6.3 erratum RHSA-2012:0874:
https://rhn.redhat.com/errata/RHSA-2012-
Bugzilla
CVE-2012-0874 JBoss invoker servlets do not require authentication
bugzilla·2012-02-21·CVSS 6.8
CVE-2012-0874 [MEDIUM] CVE-2012-0874 JBoss invoker servlets do not require authentication
CVE-2012-0874 JBoss invoker servlets do not require authentication
The JMXInvokerHAServlet and EJBInvokerHAServlet invoker servlets allow unauthenticated access by default in some profiles. Due to the second layer of authentication provided by the security interceptor, there is no way to directly exploit this flaw. If a user misconfigured the security interceptor or inadvertently disabled it, this flaw would be exploitable. A remote attacker could exploit this flaw to invoke MBean methods and run arbitrary code in the context of the user running the JBoss server.
Discussion:
Acknowledgements:
This issue was discovered by David Jorm of the Red Hat Security Response Team.
---
This issue has been addressed in following products:
JBoss Enterprise Application Platform 5.2.0
Via RHSA-201
Checkpoint
SpeakUp: A New Undetected Backdoor Linux Trojan
blogs_checkpoint·2019-02-04
CVE-2018-20062 SpeakUp: A New Undetected Backdoor Linux Trojan
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## SpeakUp: A New Undetected Backdoor Linux Trojan
Check Point Research has discovered a new campaign exploiting Linux servers to implant a new Backdoor Trojan.
Dubbed ‘SpeakUp’, the new Tro
Tenable
SamSam Ransomware: How to Identify and Mitigate the Risk
blogs_tenable·2018-03-28
SamSam Ransomware: How to Identify and Mitigate the Risk
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
SamSam Ransomware: How to Identify and Mitigate the Risk
blogs_tenable·2018-03-28
SamSam Ransomware: How to Identify and Mitigate the Risk
Blog / Cyber Exposure Alerts
Subscribe
# SamSam Ransomware: How to Identify and Mitigate the Risk
Tenable Research
March 28, 2018
3 Min Read
SamSam ransomware, which hit the city of Atlanta's systems in late March 2018, continues to be a threat. The most recent iteration leverages brute force remote desktop protocol (RDP) as an attack vector.
#### Updated on August 22, 2018
The latest iteration of SamSam attacks primarily leverages brute force RDP via tools like NLBrute while it previously leveraged JBoss/deserialization vulnerabilities. Plugin 66173 will detect exposure of remote RDP targets (rdp_logon_screen.nbin)
Remote RDP widens your attack surface and can be an easy way for attackers to get into your network. If you must use remote RDP, Two-Factor Authentication (2FA) along w
http://archives.neohapsis.com/archives/bugtraq/2013-12/0134.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0191.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0192.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0193.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0194.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0195.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0196.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0197.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0198.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0221.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0533.htmlhttp://secunia.com/advisories/51984http://secunia.com/advisories/52054http://securitytracker.com/id?1028042http://www.exploit-db.com/exploits/30211http://www.securityfocus.com/bid/57552https://bugzilla.redhat.com/show_bug.cgi?id=795645https://exchange.xforce.ibmcloud.com/vulnerabilities/81511http://archives.neohapsis.com/archives/bugtraq/2013-12/0134.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0191.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0192.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0193.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0194.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0195.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0196.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0197.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0198.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0221.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0533.htmlhttp://secunia.com/advisories/51984http://secunia.com/advisories/52054http://securitytracker.com/id?1028042http://www.exploit-db.com/exploits/30211http://www.securityfocus.com/bid/57552https://bugzilla.redhat.com/show_bug.cgi?id=795645https://exchange.xforce.ibmcloud.com/vulnerabilities/81511
2013-02-05
Published
Exploited in the wild