VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 35 of 156
  • CVE-2022-36978CriMar 29, 2023
    risk 0.64cvss 9.8epss 0.07

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists…

  • CVE-2022-36977CriMar 29, 2023
    risk 0.64cvss 9.8epss 0.07

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists…

  • CVE-2023-28667CriMar 22, 2023
    risk 0.64cvss 9.8epss 0.01

    The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue. The tve_labels parameter of the tve_api_form_submit action is passed to the PHP unserialize() function without being sanitized or verified, and as a result…

  • CVE-2023-26779CriMar 3, 2023
    risk 0.64cvss 9.8epss 0.01

    CleverStupidDog yf-exam v 1.8.0 is vulnerable to Deserialization which can lead to remote code execution (RCE).

  • CVE-2022-37936CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated Java deserialization vulnerability in Serviceguard Manager

  • CVE-2023-26326CriFeb 23, 2023
    risk 0.64cvss 9.8epss 0.04

    The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issue to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects…

  • CVE-2023-21707HigFeb 14, 2023
    risk 0.64cvss 8.8epss 0.82

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2022-45982CriFeb 8, 2023
    risk 0.64cvss 9.8epss 0.01

    thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

  • CVE-2023-24162CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.

  • CVE-2022-46478CriJan 13, 2023
    risk 0.64cvss 9.8epss 0.01

    The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrary commands via crafted Hessian serialized data.

  • CVE-2022-41778CriJan 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon…

  • CVE-2021-32824CriJan 3, 2023
    risk 0.64cvss 9.8epss 0.03

    Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arbitrary bean manipulation in the Telnet handler. The Dubbo main service port can be used to access a Telnet Handler which offers…

  • CVE-2021-38241CriDec 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro framework.

  • CVE-2022-44351CriDec 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Skycaiji v2.5.1 was discovered to contain a deserialization vulnerability via /SkycaijiApp/admin/controller/Mystore.php.

  • CVE-2022-44371CriDec 7, 2022
    risk 0.64cvss 9.8epss 0.01

    hope-boot 1.0.0 has a deserialization vulnerability that can cause Remote Code Execution (RCE).

  • CVE-2022-46366CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.04

    Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. NOTE: This vulnerability only affects Apache Tapestry version…

  • CVE-2022-45136CriNov 14, 2022
    risk 0.64cvss 9.8epss 0.02

    Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the JDBC URL used or cause the underlying database server to return malicious data. The mySQL JDBC driver in particular is known to be vulnerable to this class of…

  • CVE-2022-45378CriNov 14, 2022
    risk 0.64cvss 9.8epss 0.02

    In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the classpath that meet certain criteria. Depending on what classes are available on the classpath this might even…

  • CVE-2022-38652CriNov 12, 2022
    risk 0.64cvss 9.9epss 0.01

    A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerability enables a malicious authenticated user to run arbitrary code or malware within a Hyperic Agent instance and its host operating system with the privileges of…

  • CVE-2022-44562CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.