cbcvebase.
CVE-2016-3737
published 2016-08-02

CVE-2016-3737: The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, related to…

PriorityP263critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
6.71%
93.2th percentile
The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization.

Affected

17 ranges
VendorProductVersion rangeFixed in
redhatjboss_operations_network<= 3.3.5
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network
redhatjboss_operations_network

Detection & IOCsextracted from sources · hover to see the quote

url/jboss-remoting-servlet-invoker/ServerInvokerServlet
url/jboss-remoting-servlet-invoker/ServerInvokerServlet/?generalizeSocketException=true
port7080
uaJBossRemoting - 2.5.4.SP5 (Flounder)
filenamejboss-remoting-2.5.4.SP5.jar
filenamerhq-scripting-python-4.12.0.JON330GA.jar
pathmodules/org/rhq/server-startup/main/deployments/rq.ear/lib/
  • Alert on HTTP POST requests to /jboss-remoting-servlet-invoker/ServerInvokerServlet with the custom header 'remotingContentType: remotingContentTypeNonString', which is characteristic of JBoss Remoting protocol traffic used in exploitation.
  • Alert on HTTP POST requests to the ServerInvokerServlet endpoint bearing the User-Agent 'JBossRemoting - 2.5.4.SP5 (Flounder)', which is the agent string used in proof-of-concept exploit traffic.
  • A patched JON server will respond with 'Deserialization of InvokerTransformer is not permitted' in the HTTP 500 error body; absence of this message on a 500 response to a serialized payload POST indicates an unpatched, vulnerable server.
  • The Jython-based gadget chain abuses classes in rhq-scripting-python-4.12.0.JON330GA.jar located under modules/org/rhq/server-startup/main/deployments/rq.ear/lib/; presence of this JAR on the classpath of a JON server indicates susceptibility to the Jython deserialization gadget.
  • The deserialized payload targets org.jboss.remoting.InvocationRequest; monitor for unexpected instantiation or deserialization of this class in JVM logs as an indicator of exploitation.
  • ·CVE-2016-3737 only applies when SSL client authentication is NOT configured for JON server/agent communication. Environments with SSL mutual authentication enabled are not vulnerable.
  • ·JON 3.3.6 was believed to fix CVE-2016-3737 by updating Commons Collections, but this fix was incomplete; the Jython gadget chain remained exploitable. Full remediation requires JON 3.3.7 or SSL mutual authentication configuration.
  • ·Red Hat stated it is not feasible to correct CVE-2016-3737 with a code change alone; the authoritative mitigation is enabling SSL client certificate authentication between JON server and agents.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:N/C:P/I:P/A:C
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.