VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 33 of 156
  • CVE-2023-48886CriDec 1, 2023
    risk 0.64cvss 9.8epss 0.01

    A deserialization vulnerability in NettyRpc v1.2 allows attackers to execute arbitrary commands via sending a crafted RPC request.

  • CVE-2023-46990CriNov 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeReplace function.

  • CVE-2023-46817CriNov 3, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not properly sanitized before being used in a call to the unserialize() PHP function. This can be exploited by remote, unauthenticated attackers to inject arbitrary…

  • CVE-2023-47174CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal, a related issue to CVE-2016-1000027. Also, within the specific context of Thorn SFTP gateway, this leads to remote code execution.

  • CVE-2023-35084CriOct 18, 2023
    risk 0.64cvss 9.8epss 0.03

    Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 su3 and all previous versions, which could allow an attacker to execute commands remotely.

  • CVE-2023-43981CriOct 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Presto Changeo testsitecreator up to 1.1.1 was discovered to contain a deserialization vulnerability via the component delete_excluded_folder.php.

  • CVE-2023-5391CriOct 4, 2023
    risk 0.64cvss 9.8epss 0.01

    A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application.

  • CVE-2023-5183CriSep 27, 2023
    risk 0.64cvss 9.9epss 0.02

    Unsafe deserialization of untrusted JSON allows execution of arbitrary code on affected releases of the Illumio PCE. Authentication to the API is required to exploit this vulnerability. The flaw exists within the network_traffic API endpoint. An attacker can leverage this…

  • CVE-2023-43291CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.02

    Deserialization of Untrusted Data in emlog pro v.2.1.15 and earlier allows a remote attacker to execute arbitrary code via the cache.php component.

  • CVE-2023-40619CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP 'unserialize()' function in multiple places. An example is the functionality to manage tables in…

  • CVE-2020-19559CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Diebold Aglis XFS for Opteva v.4.1.61.1 allows a remote attacker to execute arbitrary code via a crafted payload to the ResolveMethod() parameter.

  • CVE-2023-0925CriSep 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Version 10.11 of webMethods OneData runs an embedded instance of Azul Zulu Java 11.0.15 which hosts a Java RMI registry (listening on TCP port 2099 by default) and two RMI interfaces (listening on a single, dynamically assigned TCP high port). Port 2099 serves as a Java…

  • CVE-2023-40571CriAug 25, 2023
    risk 0.64cvss 9.8epss 0.01

    weblogic-framework is a tool for detecting weblogic vulnerabilities. Versions 0.2.3 and prior do not verify the returned data packets, and there is a deserialization vulnerability which may lead to remote code execution. When weblogic-framework gets the command echo, it directly…

  • CVE-2023-3259CriAug 14, 2023
    risk 0.64cvss 9.8epss 0.01

    The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass. By manipulating the IP address field in the "iBootPduSiteAuth" cookie, a malicious agent can direct the device to connect to a rouge database.Successful exploitation…

  • CVE-2023-37895CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.03

    Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (including) 2.20.10 (stable branch) and 2.21.17 (unstable branch) use the component "commons-beanutils", which contains a class that…

  • CVE-2023-26512CriJul 17, 2023
    risk 0.64cvss 9.8epss 0.01

    CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via rabbitmq messages. Users can…

  • CVE-2023-25770CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.

  • CVE-2023-34347CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    ​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contains classes that cannot be deserialized, which could allow an attack to remotely execute arbitrary code.

  • CVE-2023-28323CriJul 1, 2023
    risk 0.64cvss 9.8epss 0.03

    A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights. This exploit could potentially be used in conjunction with other OS (Operating System) vulnerabilities to escalate privileges on the machine…

  • CVE-2023-35839CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    A bypass in the component sofa-hessian of Solon before v2.3.3 allows attackers to execute arbitrary code via providing crafted payload.