Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qppp-w788-jhgh

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL loading of Java MBeans, which allows remote attackers to execute arbitrary Java code by registering MBeans.

The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL loading of Java MBeans, which allows remote attackers to execute arbitrary Java code by registering MBeans.

EPSS

Процентиль: 64%
0.00476
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-669

Связанные уязвимости

CVSS3: 9.8
nvd
больше 9 лет назад

The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL loading of Java MBeans, which allows remote attackers to execute arbitrary Java code by registering MBeans.

EPSS

Процентиль: 64%
0.00476
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-669