← Back

CVE-2013-2165

nvd nist
Published: Jul 23, 2013Modified: Apr 29, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss Enterprise Application Platform through 4.3.0 CP10 and 5.x through 5.2.0, Red Hat JBoss BRMS through 5.3.1, Red Hat JBoss SOA Platform through 4.3.0 CP05 and 5.x through 5.3.1, Red Hat JBoss Portal through 4.3 CP07 and 5.x through 5.2.2, and Red Hat JBoss Operations Network through 2.4.2 and 3.x through 3.1.2 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data.

Affected (99)

8 products
Jboss Enterprise Brms Platform
Jboss Enterprise Portal Platform
Jboss Enterprise Soa Platform
Jboss Enterprise Web Platform
Jboss Operations Network
Jboss Web Framework Kit
Richfaces
Configuration A
99 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 4.3.0
Version 4.3.0 cp10
Version 5.0.0
Version 5.0.1
Version 5.1.0
Version 5.1.1
Version 5.1.2
Version 5.2.0
Redhat
Version 5.0.0
Version 5.0.1
Version 5.0.2
Version 5.1.0
Version 5.2.0
Version 5.3.0
Version 5.3.1
Redhat
Version 4.3.0 cp03
Version 4.3.0 cp04
Version 4.3.0 cp05
Version 4.3.0 cp06
Version 4.3.0 cp07
Version 5.0.0
Version 5.0.1
Version 5.1.0
Version 5.1.1
Version 5.2.0
Version 5.2.1
Version 5.2.2
Redhat
Version 4.2.0
Version 4.2.0 cp01
Version 4.2.0 cp02
Version 4.2.0 cp03
Version 4.2.0 cp04
Version 4.2.0 cp05
Version 4.2.0 tp02
Version 4.3.0
Version 4.3.0 cp01
Version 4.3.0 cp02
Version 4.3.0 cp03
Version 4.3.0 cp04
Version 4.3.0 cp05
Version 5.0.0
Version 5.0.1
Version 5.0.2
Version 5.1.0
Version 5.1.1
Version 5.2.0
Version 5.3.0
Version 5.3.1
Redhat
Version 5.1.0
Version 5.1.1
Version 5.1.2
Version 5.2.0
Redhat
Version 1.0.0
Version 2.0.0
Version 2.0.1
Version 2.1.0
Version 2.2
Version 2.3.1
Version 2.3
Version 2.4.1
Version 2.4.2
Version 2.4
Version 3.0.1
Version 3.0
Version 3.1.1
Version 3.1.2
Version 3.1
Redhat
Up to 2.2.0
Version 1.0.0
Version 1.1.0
Version 1.2.0
Version 2.0.0
Version 2.1.0
Redhat
Version 3.1.0
Version 3.1.1
Version 3.1.2
Version 3.1.3
Version 3.1.4
Version 3.1.5
Version 3.1.6
Version 3.2.0
Version 3.2.0 sr1
Version 3.2.1
Version 3.2.2
Version 3.3.0
Version 3.3.1
Version 3.3.2
Version 3.3.2 sr1
Version 3.3.3
Version 4.0.0
Version 4.1.0
Version 4.2.0
Version 4.2.1
Version 4.2.2
Version 4.2.3
Version 4.3.0
Version 4.3.1
Version 4.5.0 alpha1
Version 5.0.0 alpha1

Related CWEs

References (22)

Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory

Timeline

No history available yet.