CVE-2013-1777
published 2013-07-11CVE-2013-1777: The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other…
PriorityP356critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
9.81%
95.0th percentile
The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not properly implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | geronimo | — | — |
| ibm | websphere_application_server | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Geronimo JMX Remoting functionality allows remote code execution in 3.x before v3.0.1
osv·2022-05-17
CVE-2013-1777 [HIGH] Apache Geronimo JMX Remoting functionality allows remote code execution in 3.x before v3.0.1
Apache Geronimo JMX Remoting functionality allows remote code execution in 3.x before v3.0.1
The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not properly implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object.
GHSA
Apache Geronimo JMX Remoting functionality allows remote code execution in 3.x before v3.0.1
ghsa·2022-05-17
CVE-2013-1777 [HIGH] CWE-94 Apache Geronimo JMX Remoting functionality allows remote code execution in 3.x before v3.0.1
Apache Geronimo JMX Remoting functionality allows remote code execution in 3.x before v3.0.1
The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not properly implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object.
Red Hat
geronimo: Improper RMI classloader implementation in JMX remoting functionality leading to arbitrary code execution
vendor_redhat·2013-07-01·CVSS 10.0
CVE-2013-1777 [CRITICAL] geronimo: Improper RMI classloader implementation in JMX remoting functionality leading to arbitrary code execution
geronimo: Improper RMI classloader implementation in JMX remoting functionality leading to arbitrary code execution
The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not properly implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object.
Statement: Not affected. This flaw does not affect Apache Geronimo as shipped with various Red Hat products, as the affected subsystem is not included in these products.
Package: geronimo-specs (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.7.0-openjdk (Red Hat Enterprise Linux 5) - Not affected
Package: mx4j (Red Hat Enterprise Li
No detection rules found.
No public exploits indexed.
arXiv
An In-depth Study of Java Deserialization Remote-Code Execution Exploits and Vulnerabilities
arxiv_fulltext·2022-08-17
An In-depth Study of Java Deserialization Remote-Code Execution Exploits and Vulnerabilities
An In-depth Study of Java Deserialization Remote-Code Execution Exploits and Vulnerabilities
[Imen Sayar]Imen Sayar^
[email protected]
University of Toulouse
Blagnac
France
31070
^ Part of this research was conducted when Imen Sayar was at the University of Luxembourg
[Alexandre Bartel]Alexandre Bartel^*
[email protected]
Umeå University
MIT-Huset
Umeå
Sweden
^*Part of this research was conducted when Alexandre Bartel was at the University of Luxembourg and the University of Copenhagen.
Eric Bodden
[email protected]
Paderborn University
Paderborn
Germany
Yves Le Traon
[email protected]
University of Luxembourg
6, rue Richard Coudenhove-Kalergi
Kirchberg Campus
Luxembourg
L-1359
## Abstract
Nowadays, an increasing number of applications uses deserializatio
Bugzilla
CVE-2013-4169 gdm: TOCTTOU race condition on /tmp/.X11-unix
bugzilla·2013-07-25·CVSS 6.9
CVE-2013-4169 [MEDIUM] CVE-2013-4169 gdm: TOCTTOU race condition on /tmp/.X11-unix
CVE-2013-4169 gdm: TOCTTOU race condition on /tmp/.X11-unix
Vladz reported that GDM versions < 2.21.1 were vulnerable to a TOCTTOU (time of check to time of use) flaw in the way that GDM checked for the existence of, and created if missing, the /tmp/.X11-unix/ special directory. A local attacker could use this flaw to overwrite arbitrary file contents via symbolic link attacks or to manipulate the contents of arbitrary files, including those files owned by the root user that would normally be inaccessible. This is because GDM will chown /tmp/.X11-unix to the user and group root, but also changes the permissions to 1777.
Newer versions of GDM no longer create the /tmp/.X11-unix/ directory and are thus not vulnerable to this flaw.
Acknowledgements:
Red Hat would like to thank the resear
Bugzilla
CVE-2013-1777 geronimo: Improper RMI classloader implementation in JMX remoting functionality leading to arbitrary code execution
bugzilla·2013-07-12·CVSS 10.0
CVE-2013-1777 [CRITICAL] CVE-2013-1777 geronimo: Improper RMI classloader implementation in JMX remoting functionality leading to arbitrary code execution
CVE-2013-1777 geronimo: Improper RMI classloader implementation in JMX remoting functionality leading to arbitrary code execution
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-1777 to the following vulnerability:
The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not property implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object.
References:
[1] http://archives.neohapsis.com/archives/bugtraq/2013-07/0008.html
[2] http://geronimo.apache.org/30x-security-report.html
[3] http://www-01.ibm.com/support/docview.wss?uid=swg21643282
[4] https://issues.apache.org
http://archives.neohapsis.com/archives/bugtraq/2013-07/0008.htmlhttp://geronimo.apache.org/30x-security-report.htmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21643282https://issues.apache.org/jira/browse/GERONIMO-6477http://archives.neohapsis.com/archives/bugtraq/2013-07/0008.htmlhttp://geronimo.apache.org/30x-security-report.htmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21643282https://issues.apache.org/jira/browse/GERONIMO-6477
2013-07-11
Published