CVE-2013-1777
CVE-2013-1777 is a critical-severity vulnerability in Apache Geronimo with a CVSS 2.0 base score of 10.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-94.
Key facts
- Severity: Critical (CVSS 2.0 base score 10.0)
- EPSS exploit prediction: 10% (95th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-94
- Affected product: Apache Geronimo
- Published:
- Last modified:
Description
The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not properly implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object.
Frequently asked questions
- What is CVE-2013-1777?
- The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not properly implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object.
- How severe is CVE-2013-1777?
- CVE-2013-1777 has a CVSS 2.0 base score of 10.0, rated critical severity.
- Is CVE-2013-1777 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 10% (95th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2013-1777?
- CVE-2013-1777 primarily affects Apache Geronimo. In total, 4 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2013-1777?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2013-1777 published?
- CVE-2013-1777 was published on 2013-07-11 and last updated on 2026-06-16.
References
- http://archives.neohapsis.com/archives/bugtraq/2013-07/0008.html
- http://geronimo.apache.org/30x-security-report.html
- http://www-01.ibm.com/support/docview.wss?uid=swg21643282
- https://issues.apache.org/jira/browse/GERONIMO-6477
Affected products (4)
- cpe:2.3:a:apache:geronimo:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:geronimo:3.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:apache:geronimo:3.0:m1:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:3.0.0.3:-:community:*:*:*:*:*
More vulnerabilities in Apache Geronimo
- CVE-2007-4548 — Critical (CVSS 10.0): The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed…
- CVE-2008-5518 — Critical (CVSS 9.4): Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server…
- CVE-2011-5034 — High (CVSS 7.8): Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger…
- CVE-2007-5797 — High (CVSS 7.5): SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows…
- CVE-2009-0039 — Medium (CVSS 6.8): Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo…
- CVE-2007-5085 — Medium (CVSS 5.0): Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to…
All CVEs affecting Apache Geronimo →
Other CWE-94 (Code Injection) vulnerabilities
- CVE-2026-105857 — Critical (CVSS 10.0): Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions…
- CVE-2026-55107 — Critical (CVSS 10.0): Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted…
- CVE-2026-96349 — Critical (CVSS 10.0): Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.
- CVE-2026-102425 — Critical (CVSS 10.0): Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa…
- CVE-2026-89275 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…
- CVE-2026-84412 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…