JBoss InvokerTransformer Remote Code Execution

Description
  • It was found that the Apache commons-collections library permitted code execution when deserializing objects involving a specially constructed chain of classes. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using the commons-collections library.
Remediation
  • Upgrade to the latest version of JBoss.
References