Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4f4h-6cgm-pgpx

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product allows a remote attacker to inject unsecure serialized Java object using a specially crafted HTTP request, resulting in an unauthenticated remote code execution on the server.

Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product allows a remote attacker to inject unsecure serialized Java object using a specially crafted HTTP request, resulting in an unauthenticated remote code execution on the server.

EPSS

Процентиль: 94%
0.14326
Средний

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product allows a remote attacker to inject unsecure serialized Java object using a specially crafted HTTP request, resulting in an unauthenticated remote code execution on the server.

EPSS

Процентиль: 94%
0.14326
Средний

Дефекты

CWE-502