Логотип exploitDog
bind:CVE-2022-45378
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-45378

Количество 2

Количество 2

nvd логотип

CVE-2022-45378

около 3 лет назад

In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the classpath that meet certain criteria. Depending on what classes are available on the classpath this might even lead to arbitrary remote code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-789v-h9hw-38pg

около 3 лет назад

Apache SOAP contains unauthenticated RPCRouterServlet

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-45378

In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the classpath that meet certain criteria. Depending on what classes are available on the classpath this might even lead to arbitrary remote code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 9.8
5%
Низкий
около 3 лет назад
github логотип
GHSA-789v-h9hw-38pg

Apache SOAP contains unauthenticated RPCRouterServlet

CVSS3: 9.8
5%
Низкий
около 3 лет назад

Уязвимостей на страницу