CyberSec.Space Logo
返回 CVE 浏览器

CVE-2017-15708

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1300%
EPSS Percentile11.30th
Published2017年12月11日
Last Modified2026年5月13日

Vulnerability Description

In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) allows remote code execution attacks that can be performed by injecting specially crafted serialized objects. And the presence of Apache Commons Collections 3.2.1 (commons-collections-3.2.1.jar) or previous versions in Synapse distribution makes this exploitable. To mitigate the issue, we need to limit RMI access to trusted users only. Further upgrading to 3.0.1 version will eliminate the risk of having said Commons Collection version. In Synapse 3.0.1, Commons Collection has been updated to 3.2.2 version.

Affected Platforms (CPE)

📦
Apache

Synapse

= 1.0
📦
Apache

Synapse

= 1.1
📦
Apache

Synapse

= 1.1.1
📦
Apache

Synapse

= 1.1.2
📦
Apache

Synapse

= 1.2
📦
Apache

Synapse

= 2.0.0
📦
Apache

Synapse

= 2.1.0
📦
Apache

Synapse

= 3.0.0
📦
Oracle

Financial Services Market Risk Measurement And Management

= 8.0.6
📦
Oracle

Financial Services Market Risk Measurement And Management

= 8.0.8
📦
Oracle

Peoplesoft Enterprise Peopletools

= 8.56
📦
Oracle

Peoplesoft Enterprise Peopletools

= 8.57

References & Advisories

相关漏洞威胁