VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,308)

page 120 of 166
  • CVE-2022-22958HigApr 13, 2022
    risk 0.47cvss 7.2epss 0.03

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which…

  • CVE-2022-24282HigMar 8, 2022
    risk 0.47cvss 7.2epss 0.01

    A vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions). The affected system allows to upload JSON objects that are deserialized to Java objects. Due to insecure deserialization of…

  • CVE-2022-21828HigMar 4, 2022
    risk 0.47cvss 7.2epss 0.04

    A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connect server using a unspecified attack vector in Incapptic Connect version 1.40.0, 1.39.1, 1.39.0, 1.38.1, 1.38.0, 1.37.1, 1.37.0, 1.36.0, 1.35.5, 1.35.4 and…

  • CVE-2021-20318HigDec 23, 2021
    risk 0.47cvss 7.2epss 0.02

    The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using a JMS ObjectMessage.

  • CVE-2021-40843HigOct 13, 2021
    risk 0.47cvss 7.3epss 0.00

    Proofpoint Insider Threat Management Server contains an unsafe deserialization vulnerability in the Web Console. An attacker with write access to the local database could cause arbitrary code to execute with SYSTEM privileges on the underlying server when a Web Console user…

  • CVE-2021-33728HigOct 12, 2021
    risk 0.47cvss 7.2epss 0.02

    A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to upload JSON objects that are deserialized to JAVA objects. Due to insecure deserialization of user-supplied content by the affected software, a privileged attacker…

  • CVE-2021-38585HigAug 11, 2021
    risk 0.47cvss 7.2epss 0.01

    The WHM Locale Upload feature in cPanel before 98.0.1 allows unserialization attacks (SEC-585).

  • CVE-2021-36766HigJul 30, 2021
    risk 0.47cvss 7.2epss 0.04

    Concrete5 through 8.5.5 deserializes Untrusted Data. The vulnerable code is located within the controllers/single_page/dashboard/system/environment/logging.php Logging::update_logging() method. User input passed through the logFile request parameter is not properly sanitized…

  • CVE-2021-29150HigJul 8, 2021
    risk 0.47cvss 7.2epss 0.01

    A remote insecure deserialization vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

  • CVE-2021-25152HigApr 28, 2021
    risk 0.47cvss 7.2epss 0.01

    A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

  • CVE-2021-29654HigApr 14, 2021
    risk 0.47cvss 7.2epss 0.02

    AjaxSearchPro before 4.20.8 allows Deserialization of Untrusted Data (in the import database feature of the administration panel), leading to Remote Code execution.

  • CVE-2020-36179HigJan 7, 2021
    risk 0.47cvss 8.1epss 0.21

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.

  • CVE-2020-36188HigJan 6, 2021
    risk 0.47cvss 8.1epss 0.11

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource.

  • CVE-2020-10657HigJan 6, 2021
    risk 0.47cvss 7.2epss 0.03

    The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM web console's ImportAlertRules feature. The vulnerability allows a remote attacker (with admin or config-admin privileges in the console) to execute…

  • CVE-2020-35728HigDec 27, 2020
    risk 0.47cvss 8.1epss 0.13

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).

  • CVE-2020-28948HigNov 19, 2020
    risk 0.47cvss 7.8epss 0.47

    Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

  • CVE-2020-14030HigSep 30, 2020
    risk 0.47cvss 7.2epss 0.02

    An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. It stores SMS messages in .NET serialized format on the filesystem. By generating (and writing to the disk) malicious .NET serialized files, an attacker can trick the product into deserializing them, resulting in…

  • CVE-2020-11467HigApr 1, 2020
    risk 0.47cvss 7.2epss 0.04

    An issue was discovered in Deskpro before 2019.8.0. This product enables administrators to modify the helpdesk interface by editing /portal/api/style/edit-theme-set/template-sources theme templates, and uses TWIG as its template engine. While direct access to self and _self…

  • CVE-2019-5326HigFeb 27, 2020
    risk 0.47cvss 7.2epss 0.02

    An administrative application user of or application user with write access to Aruba Airwave VisualRF is able to obtain code execution on the AMP platform. This is possible due to the ability to overwrite a file on disk which is subsequently deserialized by the Java application…

  • CVE-2020-8801HigFeb 13, 2020
    risk 0.47cvss 7.2epss 0.03

    SuiteCRM through 7.11.11 allows PHAR Deserialization.