Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4238-grjh-g4xm

Опубликовано: 11 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run.

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run.

EPSS

Процентиль: 37%
0.00439
Низкий

8.1 High

CVSS3

Дефекты

CWE-829

Связанные уязвимости

CVSS3: 8.1
redhat
7 дней назад

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run.

CVSS3: 8.1
nvd
7 дней назад

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run.

EPSS

Процентиль: 37%
0.00439
Низкий

8.1 High

CVSS3

Дефекты

CWE-829