Critical severity9.8NVD Advisory· Published Feb 17, 2021· Updated Jun 17, 2026
CVE-2021-22855
CVE-2021-22855
Description
The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can send malicious serialized objects to execute arbitrary commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3(expand)+ 1 more
- (no CPE)
- (no CPE)range: 0 7.3.2020.1013
- cpe:2.3:a:hr_portal_project:hr_portal:7.3.2020.1013:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- www.chtsecurity.com/news/d334641f-2b28-4eab-a5ed-c6ec6740557envdThird Party Advisory
- www.twcert.org.tw/tw/cp-132-4405-2ddde-1.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.