VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 36 of 156
  • CVE-2022-44562CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.

  • CVE-2022-44559CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.

  • CVE-2022-44558CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.

  • CVE-2022-44542CriNov 1, 2022
    risk 0.64cvss 9.8epss 0.01

    lesspipe before 2.06 allows attackers to execute code via Perl Storable (pst) files, because of deserialized object destructor execution via a key/value pair in a hash.

  • CVE-2022-36958HigOct 20, 2022
    risk 0.64cvss 8.8epss 0.83

    SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute arbitrary commands.

  • CVE-2022-43019CriOct 19, 2022
    risk 0.64cvss 9.8epss 0.02

    OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.

  • CVE-2022-39198CriOct 18, 2022
    risk 0.64cvss 9.8epss 0.03

    A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.17 and prior versions; Apache Dubbo 3.0.x version 3.0.11 and prior versions; Apache…

  • CVE-2022-40889CriOct 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php.

  • CVE-2018-18447CriOct 12, 2022
    risk 0.64cvss 9.8epss 0.01

    dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 2 of 2).

  • CVE-2018-18446CriOct 12, 2022
    risk 0.64cvss 9.8epss 0.01

    dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 1 of 2).

  • CVE-2022-41237CriSep 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

  • CVE-2022-29063CriSep 2, 2022
    risk 0.64cvss 9.8epss 0.04

    The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server start-up or on a server…

  • CVE-2022-37021CriAug 31, 2022
    risk 0.64cvss 9.8epss 0.02

    Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. Any user still on Java 8 who wishes to protect against deserialization attacks involving JMX or RMI should upgrade to Apache Geode…

  • CVE-2022-35223CriAug 2, 2022
    risk 0.64cvss 9.8epss 0.02

    EasyUse MailHunter Ultimate’s cookie deserialization function has an inadequate validation vulnerability. Deserializing a cookie containing malicious payload will trigger this insecure deserialization vulnerability, allowing an unauthenticated remote attacker to execute…

  • CVE-2021-41419CriJul 18, 2022
    risk 0.64cvss 9.8epss 0.09

    QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization.

  • CVE-2022-29875CriJun 1, 2022
    risk 0.64cvss 9.8epss 0.02

    A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC20D), NAEOTOM Alpha (All VA40 versions < VA40 SP2), SOMATOM…

  • CVE-2022-29363CriMay 12, 2022
    risk 0.64cvss 9.8epss 0.01

    Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. This vulnerability allows attackers to getshell via writing arbitrary files.

  • CVE-2020-23621CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.02

    The Java Remote Management Interface of all versions of SVI MS Management System was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object.

  • CVE-2020-23620CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.02

    The Java Remote Management Interface of all versions of Orlansoft ERP was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object.

  • CVE-2022-25767CriMay 1, 2022
    risk 0.64cvss 9.8epss 0.03

    All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets.