Critical severity9.8NVD Advisory· Published Jan 13, 2023· Updated Jun 17, 2026
CVE-2022-46478
CVE-2022-46478
Description
The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrary commands via crafted Hessian serialized data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:datax-web_project:datax-web:*:*:*:*:*:*:*:*Range: >=1.0.0,<=2.1.2
- datax-web/datax-webdescription
- Range: v1.0.0, v2.0.0 to v2.1.2
Patches
Vulnerability mechanics
References
1- github.com/WeiYe-Jing/datax-web/issues/587nvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.