CVE-2013-2165 is a critical deserialization vulnerability affecting various Red Hat JBoss products, including RichFaces, JBoss Web Framework Kit, and JBoss Enterprise Application Platform. The flaw in ResourceBuilderImpl.java allows remote attackers to execute arbitrary code by sending specially crafted serialized data, as it fails to restrict which classes can have their deserialization methods invoked. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network without authentication, leading to potential compromise of confidentiality, integrity, and availability. Despite its age, there is no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.3.0CPE matchmatch criteria | cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.3.0:*:*:*:*:*:*:* | ||
4.3.0CPE matchmatch criteria | cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.3.0:cp10:*:*:*:*:*:* | ||
5.0.0CPE matchmatch criteria | cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.0.0:*:*:*:*:*:*:* | ||
5.0.1CPE matchmatch criteria | cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.0.1:*:*:*:*:*:*:* | ||
5.1.0CPE matchmatch criteria | cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.