PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Aug 25, 2026

JBossMQ HTTP Invocation Layer (HTTPServerILServlet) - Unauthenticated Java Deserialization

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
5
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-7504
9.8
CVSS

HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Server <= Jboss 4.X does not restrict the classes for which it performs deserialization, which allows remote attackers to execute arbitrary code via crafted serialized data.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
JBossby Red Hat, Inc.
4.x
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

JBossMQ HTTP Invocation Layer (HTTPServerILServlet) - Unauthenticated Java Deserialization CVE-2017-7504 Scanner | S4E