CVE-2017-15708
published 2017-12-11CVE-2017-15708: In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0…
PriorityP270critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
17.74%
96.8th percentile
In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) allows remote code execution attacks that can be performed by injecting specially crafted serialized objects. And the presence of Apache Commons Collections 3.2.1 (commons-collections-3.2.1.jar) or previous versions in Synapse distribution makes this exploitable. To mitigate the issue, we need to limit RMI access to trusted users only. Further upgrading to 3.0.1 version will eliminate the risk of having said Commons Collection version. In Synapse 3.0.1, Commons Collection has been updated to 3.2.2 version.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | synapse | — | — |
| apache | synapse | — | — |
| apache | synapse | — | — |
| apache | synapse | — | — |
| apache | synapse | — | — |
| apache | synapse | — | — |
| apache | synapse | — | — |
| apache | synapse | — | — |
| apache_software_foundation | apache_synapse | — | — |
| apache_software_foundation | apache_synapse | — | — |
| apache_software_foundation | apache_synapse | — | — |
| apache_software_foundation | apache_synapse | — | — |
| apache_software_foundation | apache_synapse | — | — |
| apache_software_foundation | apache_synapse | — | — |
| oracle | financial_services_market_risk_measurement_and_management | — | — |
| oracle | financial_services_market_risk_measurement_and_management | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →No authentication is required by default for Java RMI in Apache Synapse; detect unauthenticated RMI connection attempts targeting Synapse instances ↗
- →Detect delivery/presence of commons-collections-3.2.1.jar (or earlier) in Apache Synapse deployments, as this library is the exploitation prerequisite ↗
- →Monitor for injection of specially crafted serialized Java objects over RMI to Apache Synapse endpoints; deserialization of malicious payloads via Commons Collections gadget chains is the attack vector ↗
- ·Apache Synapse versions 3.0.1 and all prior releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) are affected; upgrading to 3.0.1 removes the vulnerable Commons Collections version ↗
- ·Mitigation requires restricting RMI access to trusted users only; default open RMI is the root configuration weakness ↗
- ·Synapse 3.0.1 upgrades Commons Collections to 3.2.2, eliminating the gadget-chain exploitation risk from the older library ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_oracle9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: User Interface (Apache Synapse) — CVE-2017-15708
vendor_oracle·2020-07-15·CVSS 9.8
CVE-2017-15708 [CRITICAL] Oracle Oracle Financial Services Applications Risk Matrix: User Interface (Apache Synapse) — CVE-2017-15708
Oracle Oracle Financial Services Applications Risk Matrix: User Interface (Apache Synapse) vulnerability
CVE: CVE-2017-15708
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Oracle
Oracle Oracle PeopleSoft Risk Matrix: Portal (Apache Commons) — CVE-2017-15708
vendor_oracle·2020-01-15·CVSS 9.8
CVE-2017-15708 [CRITICAL] Oracle Oracle PeopleSoft Risk Matrix: Portal (Apache Commons) — CVE-2017-15708
Oracle Oracle PeopleSoft Risk Matrix: Portal (Apache Commons) vulnerability
CVE: CVE-2017-15708
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
GHSA
Remote Code Execution in Apache Synapse
ghsa·2020-11-04
CVE-2017-15708 [CRITICAL] CWE-502 Remote Code Execution in Apache Synapse
Remote Code Execution in Apache Synapse
In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) allows remote code execution attacks that can be performed by injecting specially crafted serialized objects. And the presence of Apache Commons Collections 3.2.1 (commons-collections-3.2.1.jar) or previous versions in Synapse distribution makes this exploitable. To mitigate the issue, we need to limit RMI access to trusted users only. Further upgrading to 3.0.1 version will eliminate the risk of having said Commons Collection version. In Synapse 3.0.1, Commons Collection has been updated to 3.2.2 version.
OSV
Remote Code Execution in Apache Synapse
osv·2020-11-04
CVE-2017-15708 [CRITICAL] Remote Code Execution in Apache Synapse
Remote Code Execution in Apache Synapse
In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) allows remote code execution attacks that can be performed by injecting specially crafted serialized objects. And the presence of Apache Commons Collections 3.2.1 (commons-collections-3.2.1.jar) or previous versions in Synapse distribution makes this exploitable. To mitigate the issue, we need to limit RMI access to trusted users only. Further upgrading to 3.0.1 version will eliminate the risk of having said Commons Collection version. In Synapse 3.0.1, Commons Collection has been updated to 3.2.2 version.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/102154https://lists.apache.org/thread.html/77f2accf240d25d91b47033e2f8ebec84ffbc6e6627112b2f98b66c9%40%3Cdev.synapse.apache.org%3Ehttps://lists.apache.org/thread.html/r0fb289cd38c915b9a13a3376134f96222dd9100f1ef66b41631865c6%40%3Ccommits.doris.apache.org%3Ehttps://security.gentoo.org/glsa/202107-37https://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttp://www.securityfocus.com/bid/102154https://lists.apache.org/thread.html/77f2accf240d25d91b47033e2f8ebec84ffbc6e6627112b2f98b66c9%40%3Cdev.synapse.apache.org%3Ehttps://lists.apache.org/thread.html/r0fb289cd38c915b9a13a3376134f96222dd9100f1ef66b41631865c6%40%3Ccommits.doris.apache.org%3Ehttps://security.gentoo.org/glsa/202107-37https://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.html
2017-12-11
Published