CVE-2016-3737
published 2016-08-02CVE-2016-3737: The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, related to…
PriorityP263critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
6.71%
93.2th percentile
The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_operations_network | <= 3.3.5 | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Alert on HTTP POST requests to /jboss-remoting-servlet-invoker/ServerInvokerServlet with the custom header 'remotingContentType: remotingContentTypeNonString', which is characteristic of JBoss Remoting protocol traffic used in exploitation. ↗
- →Alert on HTTP POST requests to the ServerInvokerServlet endpoint bearing the User-Agent 'JBossRemoting - 2.5.4.SP5 (Flounder)', which is the agent string used in proof-of-concept exploit traffic. ↗
- →A patched JON server will respond with 'Deserialization of InvokerTransformer is not permitted' in the HTTP 500 error body; absence of this message on a 500 response to a serialized payload POST indicates an unpatched, vulnerable server. ↗
- →The Jython-based gadget chain abuses classes in rhq-scripting-python-4.12.0.JON330GA.jar located under modules/org/rhq/server-startup/main/deployments/rq.ear/lib/; presence of this JAR on the classpath of a JON server indicates susceptibility to the Jython deserialization gadget. ↗
- →The deserialized payload targets org.jboss.remoting.InvocationRequest; monitor for unexpected instantiation or deserialization of this class in JVM logs as an indicator of exploitation. ↗
- ·CVE-2016-3737 only applies when SSL client authentication is NOT configured for JON server/agent communication. Environments with SSL mutual authentication enabled are not vulnerable. ↗
- ·JON 3.3.6 was believed to fix CVE-2016-3737 by updating Commons Collections, but this fix was incomplete; the Jython gadget chain remained exploitable. Full remediation requires JON 3.3.7 or SSL mutual authentication configuration. ↗
- ·Red Hat stated it is not feasible to correct CVE-2016-3737 with a code change alone; the authoritative mitigation is enabling SSL client certificate authentication between JON server and agents. ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:N/C:P/I:P/A:C
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JON: incomplete fix for CVE-2016-3737
vendor_redhat·2016-08-22·CVSS 9.8
CVE-2016-6330 [CRITICAL] JON: incomplete fix for CVE-2016-3737
JON: incomplete fix for CVE-2016-3737
The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-3737.
Mitigation: Apply the configuration changes described in the documentation here: https://access.redhat.com/documentation/en-US/Red_Hat_JBoss_Operations_Network/3.3/html/Admin_and_Config/JBoss_ON_and_SSL-Authentication.html
For more information, refer to https://access.redhat.com/articles/2570101.
Package: Core Server (Red Hat JBoss Operations Network 3) - Will not fix
Red Hat
JON: The agent/server communication deserializes data, and does not require authentication
vendor_redhat·2016-05-06·CVSS 9.8
CVE-2016-3737 [CRITICAL] JON: The agent/server communication deserializes data, and does not require authentication
JON: The agent/server communication deserializes data, and does not require authentication
The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization.
It was discovered that sending specially crafted HTTP request to the JON server would allow deserialization of that message without authentication. An attacker could use this flaw to cause remote code execution.
Statement: It is not feasible to correct this issue with a code change as client SSL certificates need to be created in order to support client authentication. The installation documentation notes how to mitigate this through the creation of certificates to support SSL authentication. This mitigation is the best
GHSA
GHSA-m68x-f3rw-rxhq: The server in Red Hat JBoss Operations Network (JON) before 3
ghsa_unreviewed·2022-05-17
CVE-2016-3737 [CRITICAL] CWE-20 GHSA-m68x-f3rw-rxhq: The server in Red Hat JBoss Operations Network (JON) before 3
The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization.
GHSA
GHSA-hpgf-x5r5-6h89: The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote at
ghsa_unreviewed·2022-05-17·CVSS 9.8
CVE-2016-6330 [CRITICAL] CWE-502 GHSA-hpgf-x5r5-6h89: The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote at
The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-3737.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-6330 JON: incomplete fix for CVE-2016-3737
bugzilla·2016-08-22·CVSS 9.8
CVE-2016-6330 [CRITICAL] CVE-2016-6330 JON: incomplete fix for CVE-2016-3737
CVE-2016-6330 JON: incomplete fix for CVE-2016-3737
The fix for CVE-2016-3737 in JON 3.3.6 was deemed to be incomplete. While we included a documentation fix in the installation guide which explained how to mitigate the issue, we provided misleading information in the security advisory for JON 3.3.6, that it was fixed by that update, which was not correct. To fix this issue, you need to configure SSL authentication for the JON Server/Agent communication. Please see the documentation for details on how to do that: https://access.redhat.com/documentation/en-US/Red_Hat_JBoss_Operations_Network/3.3/html/Admin_and_Config/JBoss_ON_and_SSL-Authentication.html
It is not feasible to correct this issue with a code change as client SSL certificates need to be created in order to support client authe
Bugzilla
CVE-2016-3737 JON: The agent/server communication deserializes data, and does not require authentication
bugzilla·2016-05-06·CVSS 9.8
CVE-2016-3737 [CRITICAL] CVE-2016-3737 JON: The agent/server communication deserializes data, and does not require authentication
CVE-2016-3737 JON: The agent/server communication deserializes data, and does not require authentication
JBoss Operations Network server deserializes data, and does not require authentication. A malicious payload could be crafted, and sent to a server which when deserialized causes remote code execution.
Discussion:
A workaround for this issue it to enable client authentication between servers and agents:
https://access.redhat.com/documentation/en-US/Red_Hat_JBoss_Operations_Network/3.3/html/Admin_and_Config/JBoss_ON_and_SSL-Authentication.html
---
This issue has been addressed in the following products:
Red Hat JBoss Operations Network 3.3.6
Via RHSA-2016:1519 https://rhn.redhat.com/errata/RHSA-2016-1519.html
---
Despite it previously being described as a workaround, the configu
Tenable
Expanding on a Known Vulnerability: Attacking with Jython
blogs_tenable·2016-09-07·CVSS 9.8
CVE-2016-3737 [CRITICAL] Expanding on a Known Vulnerability: Attacking with Jython
Blog /
Subscribe
# Expanding on a Known Vulnerability: Attacking with Jython
Jacob Baines
September 7, 2016
24 Min Read
As a Reverse Engineer at Tenable, I investigate disclosed vulnerabilities in order to write remote plugins for the Nessus® vulnerability scanner. Each investigation is unique and presents its own set of challenges. In some cases, new vulnerabilities are uncovered. One such investigation happened earlier this year when I was analyzing CVE-2016-3737 in Red Hat JBoss Operations Network (JON).
When I began looking into CVE-2016-3737, the entry in the National Vulnerability Database was empty but there was a Red Hat security advisory that read:
> It was discovered that sending specially crafted HTTP request to the JON server would allow deserialization of that message w
Tenable
Expanding on a Known Vulnerability: Attacking with Jython
blogs_tenable·2016-09-07
Expanding on a Known Vulnerability: Attacking with Jython
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
[R2] Red Hat JBoss Operations Network /jboss-remoting-servlet-invoker/ServerInvokerServlet Jython Deserialization Remote Code Execution
blogs_tenable·2016-07-20
[R2] Red Hat JBoss Operations Network /jboss-remoting-servlet-invoker/ServerInvokerServlet Jython Deserialization Remote Code Execution
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://rhn.redhat.com/errata/RHSA-2016-1519.htmlhttp://www.securitytracker.com/id/1036507https://bugzilla.redhat.com/show_bug.cgi?id=1333618https://www.tenable.com/security/research/tra-2016-22http://rhn.redhat.com/errata/RHSA-2016-1519.htmlhttp://www.securitytracker.com/id/1036507https://bugzilla.redhat.com/show_bug.cgi?id=1333618https://www.tenable.com/security/research/tra-2016-22
2016-08-02
Published