JBossMQ HTTP Invocation Layer (HTTPServerILServlet) - Unauthenticated Java Deserialization
CVE-2017-7504
Verified
Description
The JMS over HTTP Invocation Layer in JBossMQ, as implemented in HTTPServerILServlet.java in JBoss Application Server (AS) 4.x and earlier, does not properly restrict the classes that can be deserialized from the raw POST body. This allows remote attackers to execute arbitrary code or cause a denial of service (application crash or other impacts) via crafted serialized objects, due to insecure Java object deserialization.
Severity
Critical
CVSS Score
9.8
Exploit Probability
39%
Affected Product
jboss_application_server
Published Date
July 14, 2026
Template Author
jayachandran
CVE-2017-7504.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2017-7504
CWE ID:
cwe-502
Remediation Steps
Upgrade JBoss AS to a supported EAP version, or remove the jbossmq-httpil.sar deployment if JMS-over-HTTP is not required.