/Vulnerability Library

JBossMQ HTTP Invocation Layer (HTTPServerILServlet) - Unauthenticated Java Deserialization

CVE-2017-7504
Verified

Description

The JMS over HTTP Invocation Layer in JBossMQ, as implemented in HTTPServerILServlet.java in JBoss Application Server (AS) 4.x and earlier, does not properly restrict the classes that can be deserialized from the raw POST body. This allows remote attackers to execute arbitrary code or cause a denial of service (application crash or other impacts) via crafted serialized objects, due to insecure Java object deserialization.

Severity

Critical

CVSS Score

9.8

Exploit Probability

39%

Affected Product

jboss_application_server

Published Date

July 14, 2026

Template Author

jayachandran

CVE-2017-7504.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2017-7504
CWE ID:
cwe-502

References

https://github.com/vulhub/vulhub/blob/master/jboss/CVE-2017-7504/README.mdhttps://nvd.nist.gov/vuln/detail/CVE-2017-7504

Remediation Steps

Upgrade JBoss AS to a supported EAP version, or remove the jbossmq-httpil.sar deployment if JMS-over-HTTP is not required.