Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jw8f-7679-44jm

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. The vulnerability only occurs if an undocumented customization has been applied by an administrator. IBM X-Force ID: 184585.

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. The vulnerability only occurs if an undocumented customization has been applied by an administrator. IBM X-Force ID: 184585.

EPSS

Процентиль: 91%
0.0677
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502
CWE-74

Связанные уязвимости

CVSS3: 9.8
nvd
больше 5 лет назад

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 184585.

CVSS3: 9.8
fstec
больше 5 лет назад

Уязвимость сервера приложений WebSphere Application Server, существующая из-за непринятия мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 91%
0.0677
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502
CWE-74