HTTP: Apache Dubbo HttpRemoteInvocation Insecure Deserialization

This signature detects attempts to exploit a known vulnerability against Apache Dubbo. A successful attack can lead to arbitrary code execution.

Extended Description

Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables HTTP. This issue affected Apache Dubbo 2.7.0 to 2.7.4, 2.6.0 to 2.6.7, and all 2.5.x versions.

Affected Products

Apache dubbo

Short Name
HTTP:APACHE:DUBBO-RMTINVCTN-ID
Severity
Minor
Recommended
True
Recommended Action
None
Category
HTTP
Keywords
Apache CVE-2019-17564 Deserialization Dubbo HttpRemoteInvocation Insecure
Release Date
04/30/2020
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Apache

CVSS Score

6.8

Found a potential security threat?