CVE-2013-2165
published 2013-07-23CVE-2013-2165: ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through…
PriorityP355high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
12.66%
95.8th percentile
ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss Enterprise Application Platform through 4.3.0 CP10 and 5.x through 5.2.0, Red Hat JBoss BRMS through 5.3.1, Red Hat JBoss SOA Platform through 4.3.0 CP05 and 5.x through 5.3.1, Red Hat JBoss Portal through 4.3 CP07 and 5.x through 5.2.2, and Red Hat JBoss Operations Network through 2.4.2 and 3.x through 3.1.2 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data.
Affected
85 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nuxeo | nuxeo | — | — |
| nuxeo | nuxeo | — | — |
| nuxeo | nuxeo_platform | — | — |
| nuxeo | nuxeo_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_brms_platform | — | — |
| redhat | jboss_enterprise_brms_platform | — | — |
| redhat | jboss_enterprise_brms_platform | — | — |
| redhat | jboss_enterprise_brms_platform | — | — |
| redhat | jboss_enterprise_brms_platform | — | — |
| redhat | jboss_enterprise_brms_platform | — | — |
| redhat | jboss_enterprise_brms_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Remote code execution due to insecure deserialization
osv·2022-05-13
CVE-2013-2165 [HIGH] Remote code execution due to insecure deserialization
Remote code execution due to insecure deserialization
A flaw was found in the way JBoss RichFaces handled deserialization. A remote attacker could use this flaw to trigger the execution of the deserialization methods in any serializable class deployed on the server. This could lead to a variety of security impacts depending on the deserialization logic of these classes.
GHSA
Remote code execution due to insecure deserialization
ghsa·2022-05-13
CVE-2013-2165 [HIGH] Remote code execution due to insecure deserialization
Remote code execution due to insecure deserialization
A flaw was found in the way JBoss RichFaces handled deserialization. A remote attacker could use this flaw to trigger the execution of the deserialization methods in any serializable class deployed on the server. This could lead to a variety of security impacts depending on the deserialization logic of these classes.
GHSA
GHSA-pw96-ph5x-hm7c: RichFaces implementation in Nuxeo Platform 5
ghsa_unreviewed·2022-05-05·CVSS 7.5
CVE-2013-4521 [HIGH] GHSA-pw96-ph5x-hm7c: RichFaces implementation in Nuxeo Platform 5
RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data. NOTE: this vulnerability may overlap CVE-2013-2165.
Red Hat
RichFaces: Remote code execution due to insecure deserialization
vendor_redhat·2013-07-10·CVSS 7.5
CVE-2013-2165 [HIGH] CWE-502 RichFaces: Remote code execution due to insecure deserialization
RichFaces: Remote code execution due to insecure deserialization
ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss Enterprise Application Platform through 4.3.0 CP10 and 5.x through 5.2.0, Red Hat JBoss BRMS through 5.3.1, Red Hat JBoss SOA Platform through 4.3.0 CP05 and 5.x through 5.3.1, Red Hat JBoss Portal through 4.3 CP07 and 5.x through 5.2.2, and Red Hat JBoss Operations Network through 2.4.2 and 3.x through 3.1.2 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data.
Package: RichFaces (Red Hat JBoss BRMS 5) - Affected
Package: RichFaces (Red Ha
No detection rules found.
No public exploits indexed.
arXiv
An In-depth Study of Java Deserialization Remote-Code Execution Exploits and Vulnerabilities
arxiv_fulltext·2022-08-17
An In-depth Study of Java Deserialization Remote-Code Execution Exploits and Vulnerabilities
An In-depth Study of Java Deserialization Remote-Code Execution Exploits and Vulnerabilities
[Imen Sayar]Imen Sayar^
[email protected]
University of Toulouse
Blagnac
France
31070
^ Part of this research was conducted when Imen Sayar was at the University of Luxembourg
[Alexandre Bartel]Alexandre Bartel^*
[email protected]
Umeå University
MIT-Huset
Umeå
Sweden
^*Part of this research was conducted when Alexandre Bartel was at the University of Luxembourg and the University of Copenhagen.
Eric Bodden
[email protected]
Paderborn University
Paderborn
Germany
Yves Le Traon
[email protected]
University of Luxembourg
6, rue Richard Coudenhove-Kalergi
Kirchberg Campus
Luxembourg
L-1359
## Abstract
Nowadays, an increasing number of applications uses deserializatio
CTF
angry-seam-500 / README
ctf_writeups·2016
CVE-2013-2165 angry-seam-500 / README
# HITCON CTF 2016 : angry-seam-500
**Category:** web
**Points:** 500
**Solves:**
**Description:**
> Why my teammate, Sean, is so angry?
## Write-up
(TODO)
## Other write-ups and resources
* https://github.com/Blaklis/write-ups/tree/master/hitcon
* http://vnprogramming.com/index.php/2016/10/10/web500-hitconctf-2016-and-exploit-cve-2013-2165/
Bugzilla
CVE-2013-4521 Nuxeo RichFaces: Remote code execution due to insecure deserialization
bugzilla·2013-11-06·CVSS 7.5
CVE-2013-4521 [HIGH] CVE-2013-4521 Nuxeo RichFaces: Remote code execution due to insecure deserialization
CVE-2013-4521 Nuxeo RichFaces: Remote code execution due to insecure deserialization
A flaw was found in the way Nuxeo RichFaces handled deserialization. A remote attacker could use this flaw to trigger the execution of the deserialization methods in any serializable class deployed on the server. This could lead to a variety of security impacts depending on the deserialization logic of these classes. On Nuxeo Server 5.6, 5.7.4 and 5.8, this can be used to trigger deserialization logic which leads to unauthenticated remote code execution.
Discussion:
Statement:
Not vulnerable. This flaw does not affect RichFaces as shipped with various JBoss products. These products use JBoss RichFaces, which is covered by CVE-2013-2165. This flaw pertains specifically to Nuxeo RichFaces.
---
Upstream
Bugzilla
CVE-2013-2165 JBoss RichFaces: Remote code execution due to insecure deserialization
bugzilla·2013-06-12·CVSS 7.5
CVE-2013-2165 [HIGH] CVE-2013-2165 JBoss RichFaces: Remote code execution due to insecure deserialization
CVE-2013-2165 JBoss RichFaces: Remote code execution due to insecure deserialization
A flaw was found in the way JBoss RichFaces handled deserialization. A remote attacker could use this flaw to trigger the execution of the deserialization methods in any serializable class deployed on the server. This could lead to a variety of security impacts depending on the deserialization logic of these classes.
Discussion:
This issue has been addressed in following products:
Red Hat JBoss Web Framework Kit 2.3.0
Via RHSA-2013:1041 https://rhn.redhat.com/errata/RHSA-2013-1041.html
---
This issue has been addressed in following products:
JBEWP 5 for RHEL 6
JBEWP 5 for RHEL 5
JBEWP 5 for RHEL 4
Via RHSA-2013:1043 https://rhn.redhat.com/errata/RHSA-2013-1043.html
---
This issue has been addres
http://jvn.jp/en/jp/JVN38787103/index.htmlhttp://jvndb.jvn.jp/jvndb/JVNDB-2013-000072http://packetstormsecurity.com/files/156663/Richsploit-RichFaces-Exploitation-Toolkit.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1041.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1042.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1043.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1044.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1045.htmlhttp://seclists.org/fulldisclosure/2020/Mar/21https://access.redhat.com/security/cve/CVE-2013-2165https://bugzilla.redhat.com/show_bug.cgi?id=973570http://jvn.jp/en/jp/JVN38787103/index.htmlhttp://jvndb.jvn.jp/jvndb/JVNDB-2013-000072http://packetstormsecurity.com/files/156663/Richsploit-RichFaces-Exploitation-Toolkit.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1041.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1042.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1043.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1044.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1045.htmlhttp://seclists.org/fulldisclosure/2020/Mar/21https://access.redhat.com/security/cve/CVE-2013-2165https://bugzilla.redhat.com/show_bug.cgi?id=973570
2013-07-23
Published