cbcvebase.
CVE-2017-15708
published 2017-12-11

CVE-2017-15708: In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0…

PriorityP270critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
17.74%
96.8th percentile
In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) allows remote code execution attacks that can be performed by injecting specially crafted serialized objects. And the presence of Apache Commons Collections 3.2.1 (commons-collections-3.2.1.jar) or previous versions in Synapse distribution makes this exploitable. To mitigate the issue, we need to limit RMI access to trusted users only. Further upgrading to 3.0.1 version will eliminate the risk of having said Commons Collection version. In Synapse 3.0.1, Commons Collection has been updated to 3.2.2 version.

Affected

18 ranges
VendorProductVersion rangeFixed in
apachesynapse
apachesynapse
apachesynapse
apachesynapse
apachesynapse
apachesynapse
apachesynapse
apachesynapse
apache_software_foundationapache_synapse
apache_software_foundationapache_synapse
apache_software_foundationapache_synapse
apache_software_foundationapache_synapse
apache_software_foundationapache_synapse
apache_software_foundationapache_synapse
oraclefinancial_services_market_risk_measurement_and_management
oraclefinancial_services_market_risk_measurement_and_management
oraclepeoplesoft_enterprise_peopletools
oraclepeoplesoft_enterprise_peopletools

Detection & IOCsextracted from sources · hover to see the quote

  • No authentication is required by default for Java RMI in Apache Synapse; detect unauthenticated RMI connection attempts targeting Synapse instances
  • Detect delivery/presence of commons-collections-3.2.1.jar (or earlier) in Apache Synapse deployments, as this library is the exploitation prerequisite
  • Monitor for injection of specially crafted serialized Java objects over RMI to Apache Synapse endpoints; deserialization of malicious payloads via Commons Collections gadget chains is the attack vector
  • ·Apache Synapse versions 3.0.1 and all prior releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) are affected; upgrading to 3.0.1 removes the vulnerable Commons Collections version
  • ·Mitigation requires restricting RMI access to trusted users only; default open RMI is the root configuration weakness
  • ·Synapse 3.0.1 upgrades Commons Collections to 3.2.2, eliminating the gadget-chain exploitation risk from the older library

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_oracle9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.