CVE-2017-15708 (CNNVD-201710-1018)
中文标题:
Apache Synapse 注入漏洞
英文标题:
In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI)....
漏洞描述
中文描述:
Apache Synapse是美国阿帕奇(Apache)基金会的一款轻量级ESB(企业服务总线)。Apache Commons Collections是其中的一个提供了Java集合框架的库。 Apache Synapse中的Apache Commons Collections 3.2.1(commons-collections-3.2.1.jar)及之前的版本中存在注入漏洞。远程攻击者可通过注入特制的序列化对象利用该漏洞执行代码。以下版本受到影响:Apache Synapse 3.0.0版本,2.1.0版本,2.0.0版本,1.2版本,1.1.2版本,1.1.1版本。
英文描述:
In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) allows remote code execution attacks that can be performed by injecting specially crafted serialized objects. And the presence of Apache Commons Collections 3.2.1 (commons-collections-3.2.1.jar) or previous versions in Synapse distribution makes this exploitable. To mitigate the issue, we need to limit RMI access to trusted users only. Further upgrading to 3.0.1 version will eliminate the risk of having said Commons Collection version. In Synapse 3.0.1, Commons Collection has been updated to 3.2.2 version.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Apache Software Foundation | Apache Synapse | 3.0.0 | - | - |
cpe:2.3:a:apache_software_foundation:apache_synapse:3.0.0:*:*:*:*:*:*:*
|
| Apache Software Foundation | Apache Synapse | 2.1.0 | - | - |
cpe:2.3:a:apache_software_foundation:apache_synapse:2.1.0:*:*:*:*:*:*:*
|
| Apache Software Foundation | Apache Synapse | 2.0.0 | - | - |
cpe:2.3:a:apache_software_foundation:apache_synapse:2.0.0:*:*:*:*:*:*:*
|
| Apache Software Foundation | Apache Synapse | 1.2 | - | - |
cpe:2.3:a:apache_software_foundation:apache_synapse:1.2:*:*:*:*:*:*:*
|
| Apache Software Foundation | Apache Synapse | 1.1.2 | - | - |
cpe:2.3:a:apache_software_foundation:apache_synapse:1.1.2:*:*:*:*:*:*:*
|
| Apache Software Foundation | Apache Synapse | 1.1.1 | - | - |
cpe:2.3:a:apache_software_foundation:apache_synapse:1.1.1:*:*:*:*:*:*:*
|
| apache | synapse | 1.0 | - | - |
cpe:2.3:a:apache:synapse:1.0:*:*:*:*:*:*:*
|
| apache | synapse | 1.1 | - | - |
cpe:2.3:a:apache:synapse:1.1:*:*:*:*:*:*:*
|
| apache | synapse | 1.1.1 | - | - |
cpe:2.3:a:apache:synapse:1.1.1:*:*:*:*:*:*:*
|
| apache | synapse | 1.1.2 | - | - |
cpe:2.3:a:apache:synapse:1.1.2:*:*:*:*:*:*:*
|
| apache | synapse | 1.2 | - | - |
cpe:2.3:a:apache:synapse:1.2:*:*:*:*:*:*:*
|
| apache | synapse | 2.0.0 | - | - |
cpe:2.3:a:apache:synapse:2.0.0:*:*:*:*:*:*:*
|
| apache | synapse | 2.1.0 | - | - |
cpe:2.3:a:apache:synapse:2.1.0:*:*:*:*:*:*:*
|
| apache | synapse | 3.0.0 | - | - |
cpe:2.3:a:apache:synapse:3.0.0:*:*:*:*:*:*:*
|
| oracle | financial_services_market_risk_measurement_and_management | 8.0.6 | - | - |
cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.6:*:*:*:*:*:*:*
|
| oracle | financial_services_market_risk_measurement_and_management | 8.0.8 | - | - |
cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.8:*:*:*:*:*:*:*
|
| oracle | peoplesoft_enterprise_peopletools | 8.56 | - | - |
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:*
|
| oracle | peoplesoft_enterprise_peopletools | 8.57 | - | - |
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
CVSS评分详情
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2017-15708 |
2025-11-11 15:19:20 | 2025-11-11 07:34:38 |
| NVD | nvd_CVE-2017-15708 |
2025-11-11 14:55:34 | 2025-11-11 07:43:17 |
| CNNVD | cnnvd_CNNVD-201710-1018 |
2025-11-11 15:09:54 | 2025-11-11 07:53:19 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 注入
- cnnvd_id: 未提取 -> CNNVD-201710-1018
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.CRITICAL
- cvss_score: 未提取 -> 9.8
- cvss_vector: NOT_EXTRACTED -> CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- cvss_version: NOT_EXTRACTED -> 3.1
- affected_products_count: 6 -> 18
- data_sources: ['cve'] -> ['cve', 'nvd']