VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,308)

page 35 of 166
  • CVE-2022-34268CriDec 25, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in RWS WorldServer before 11.7.3. /clientLogin deserializes Java objects without authentication, leading to command execution on the host.

  • CVE-2023-32242CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in xtemos WoodMart - Multipurpose WooCommerce Theme.This issue affects WoodMart - Multipurpose WooCommerce Theme: from n/a through 1.0.36.

  • CVE-2023-51656CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4. Users are recommended to upgrade to version 1.2.2, which fixes the issue.

  • CVE-2023-46279CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.02

    Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the latest version, which fixes the issue.

  • CVE-2023-29234CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.07

    A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 through 3.2.4. Users are recommended to upgrade to the latest version, which fixes the issue.

  • CVE-2023-48967CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Ssolon <= 2.6.0 and <=2.5.12 is vulnerable to Deserialization of Untrusted Data.

  • CVE-2023-48886CriDec 1, 2023
    risk 0.64cvss 9.8epss 0.01

    A deserialization vulnerability in NettyRpc v1.2 allows attackers to execute arbitrary commands via sending a crafted RPC request.

  • CVE-2023-46990CriNov 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeReplace function.

  • CVE-2023-46817CriNov 3, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not properly sanitized before being used in a call to the unserialize() PHP function. This can be exploited by remote, unauthenticated attackers to inject arbitrary…

  • CVE-2023-47174CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal, a related issue to CVE-2016-1000027. Also, within the specific context of Thorn SFTP gateway, this leads to remote code execution.

  • CVE-2023-35084CriOct 18, 2023
    risk 0.64cvss 9.8epss 0.03

    Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 su3 and all previous versions, which could allow an attacker to execute commands remotely.

  • CVE-2023-43981CriOct 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Presto Changeo testsitecreator up to 1.1.1 was discovered to contain a deserialization vulnerability via the component delete_excluded_folder.php.

  • CVE-2023-5391CriOct 4, 2023
    risk 0.64cvss 9.8epss 0.01

    A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application.

  • CVE-2023-5183CriSep 27, 2023
    risk 0.64cvss 9.9epss 0.02

    Unsafe deserialization of untrusted JSON allows execution of arbitrary code on affected releases of the Illumio PCE. Authentication to the API is required to exploit this vulnerability. The flaw exists within the network_traffic API endpoint. An attacker can leverage this…

  • CVE-2023-43291CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.02

    Deserialization of Untrusted Data in emlog pro v.2.1.15 and earlier allows a remote attacker to execute arbitrary code via the cache.php component.

  • CVE-2023-40619CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP 'unserialize()' function in multiple places. An example is the functionality to manage tables in…

  • CVE-2020-19559CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Diebold Aglis XFS for Opteva v.4.1.61.1 allows a remote attacker to execute arbitrary code via a crafted payload to the ResolveMethod() parameter.

  • CVE-2023-0925CriSep 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Version 10.11 of webMethods OneData runs an embedded instance of Azul Zulu Java 11.0.15 which hosts a Java RMI registry (listening on TCP port 2099 by default) and two RMI interfaces (listening on a single, dynamically assigned TCP high port). Port 2099 serves as a Java…

  • CVE-2023-40571CriAug 25, 2023
    risk 0.64cvss 9.8epss 0.01

    weblogic-framework is a tool for detecting weblogic vulnerabilities. Versions 0.2.3 and prior do not verify the returned data packets, and there is a deserialization vulnerability which may lead to remote code execution. When weblogic-framework gets the command echo, it directly…

  • CVE-2023-3259CriAug 14, 2023
    risk 0.64cvss 9.8epss 0.01

    The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass. By manipulating the IP address field in the "iBootPduSiteAuth" cookie, a malicious agent can direct the device to connect to a rouge database.Successful exploitation…