VDB
RHSA-2011:1334
RHSA-2011:1334
PUBLISHED
CVSS 7.5 HIGH
Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, and possibly other versions deserialize objects from untrusted sources, which allows remote attackers to bypass intended security restrictions and execute untrusted code by (1) serializing a java.lang.Proxy instance and using InvocationHandler, or (2) accessing internal AOP interfaces, as demonstrated using deserialization of a DefaultListableBeanFactory instance to execute arbitrary commands via the java.lang.Runtime class.
Risk Scores
CVSS 2.0
7.5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss SOA Platform 5.1 |
Timeline
- Sep 22, 2011 CVE Published
- Nov 21, 2025 CVE Updated
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2011:1334 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=soaplatform&downloadType=securityPatches&version=5.1.0+GA advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=737611 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2011/rhsa-2011_1334.json advisory
- https://access.redhat.com/security/cve/CVE-2011-2894 advisory
- https://www.cve.org/CVERecord?id=CVE-2011-2894 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-2894 advisory