« Volver al listado

CVE-2013-1777

Estado: ModificadaAlta (10)—

The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not properly implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-1777",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-07-11T22:55:00.883",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2013-07/0008.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://geronimo.apache.org/30x-security-report.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21643282",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://issues.apache.org/jira/browse/GERONIMO-6477",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2013-07/0008.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://geronimo.apache.org/30x-security-report.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21643282",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://issues.apache.org/jira/browse/GERONIMO-6477",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not properly implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object."
    },
    {
      "lang": "es",
      "value": "La funcionalidad JMX Remoting en Apache Geronimo versiones 3.x anteriores a 3.0.1, tal y como se usa en WebSphere Application Server (WAS) Community Edition de IBM versión 3.0.0.3 y otros productos, no implementa apropiadamente el cargador de clases RMI, lo que permite a los atacantes remotos ejecutar código arbitrario usando el conector JMX para enviar un objeto serializado diseñado."
    }
  ],
  "lastModified": "2026-06-16T23:52:06.200",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:geronimo:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86DD5507-6CC0-4A15-A439-DACE3FF7CA45"
            },
            {
              "criteria": "cpe:2.3:a:apache:geronimo:3.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "70CA9733-1982-4F17-9491-88031934DC5D"
            },
            {
              "criteria": "cpe:2.3:a:apache:geronimo:3.0:m1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5D93565-3338-4F68-987D-1E563F90A552"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_application_server:3.0.0.3:-:community:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "24AF96DE-D8DE-497E-9413-256E8C9977E0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}