cbcvebase.
CVE-2012-0874
published 2013-02-05

CVE-2012-0874: The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before…

PriorityP180medium6.8CVSS 2.0
AVNACMAuNCPIPAP
ITWEXPLOITVulnCheck KEVRansomware
Exploited in the wild
EPSS
15.56%
96.5th percentile
The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 do not require authentication by default in certain profiles, which might allow remote attackers to invoke MBean methods and execute arbitrary code via unspecified vectors. NOTE: this issue can only be exploited when the interceptor is not properly configured with a "second layer of authentication," or when used in conjunction with other vulnerabilities that bypass this second layer.

Affected

5 ranges
VendorProductVersion rangeFixed in
hpprocurve_manager
hpprocurve_manager
redhatjboss_enterprise_application_platform
redhatjboss_enterprise_brms_platform<= 5.3.0
redhatjboss_enterprise_web_platform

Detection & IOCsextracted from sources · hover to see the quote

urlhttp://[host]:8090/invoker/EJBInvokerServlet
urlhttps://[host]:8453//invoker/EJBInvokerServlet
path/invoker/EJBInvokerServlet/
path/invoker/JMXInvokerServlet/
port8090
port8453
otherContentType: application/x-java-serialized-object; class=org.jboss.invocation.MarshalledInvocation
  • The interceptor that blocks exploitation by default is declared in jboss-as/server/$PROFILE/deploy/jmx-invoker-service.xml; absence or misconfiguration of this file leaves the system exploitable.
  • SamSam ransomware actors exploited CVE-2012-0874 in the wild; hunt for JBoss invoker servlet access in web logs as a precursor to ransomware deployment.
  • ·The vulnerability is only directly exploitable when the security interceptor is misconfigured or disabled; a properly configured second layer of authentication in jmx-invoker-service.xml prevents exploitation.
  • ·All supported Red Hat JBoss products apply authentication to these servlet interfaces by default and are not affected; only older unsupported community releases of JBoss AS 4.x and 5.x are exposed by default.
  • ·JBoss AS (WildFly) 7.x community releases are also not affected by this issue.

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck6.8MEDIUM
vendor_redhat6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.