December 10, 2021 · Applied Cybernetics Group
CVE-2017-12149 — Red Hat JBoss Application Server
known ransomware use
Red Hat JBoss Application Server Remote Code Execution Vulnerability
- Added to KEV
2021-12-10- Federal due date
2022-06-10- Vendor
- Red Hat
- Product
- JBoss Application Server
- EPSS
- 99.9th percentile (score 0.943, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2017-12149
CISA short description
The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data.
Required action
Apply updates per vendor instructions.