CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,116)
page 36 of 156| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-44562 | Cri | 0.64 | 9.8 | 0.01 | Nov 9, 2022 | The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation. | ||
| CVE-2022-44559 | Cri | 0.64 | 9.8 | 0.01 | Nov 9, 2022 | The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation. | ||
| CVE-2022-44558 | Cri | 0.64 | 9.8 | 0.01 | Nov 9, 2022 | The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation. | ||
| CVE-2022-44542 | Cri | 0.64 | 9.8 | 0.01 | Nov 1, 2022 | lesspipe before 2.06 allows attackers to execute code via Perl Storable (pst) files, because of deserialized object destructor execution via a key/value pair in a hash. | ||
| CVE-2022-36958 | Hig | 0.64 | 8.8 | 0.83 | Oct 20, 2022 | SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute arbitrary commands. | ||
| CVE-2022-43019 | Cri | 0.64 | 9.8 | 0.02 | Oct 19, 2022 | OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality. | ||
| CVE-2022-39198 | Cri | 0.64 | 9.8 | 0.03 | Oct 18, 2022 | A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.17 and prior versions; Apache Dubbo 3.0.x version 3.0.11 and prior versions; Apache… | ||
| CVE-2022-40889 | Cri | 0.64 | 9.8 | 0.01 | Oct 18, 2022 | Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php. | ||
| CVE-2018-18447 | Cri | 0.64 | 9.8 | 0.01 | Oct 12, 2022 | dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 2 of 2). | ||
| CVE-2018-18446 | Cri | 0.64 | 9.8 | 0.01 | Oct 12, 2022 | dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 1 of 2). | ||
| CVE-2022-41237 | Cri | 0.64 | 9.8 | 0.01 | Sep 21, 2022 | Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability. | ||
| CVE-2022-29063 | Cri | 0.64 | 9.8 | 0.04 | Sep 2, 2022 | The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server start-up or on a server… | ||
| CVE-2022-37021 | Cri | 0.64 | 9.8 | 0.02 | Aug 31, 2022 | Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. Any user still on Java 8 who wishes to protect against deserialization attacks involving JMX or RMI should upgrade to Apache Geode… | ||
| CVE-2022-35223 | Cri | 0.64 | 9.8 | 0.02 | Aug 2, 2022 | EasyUse MailHunter Ultimate’s cookie deserialization function has an inadequate validation vulnerability. Deserializing a cookie containing malicious payload will trigger this insecure deserialization vulnerability, allowing an unauthenticated remote attacker to execute… | ||
| CVE-2021-41419 | Cri | 0.64 | 9.8 | 0.09 | Jul 18, 2022 | QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization. | ||
| CVE-2022-29875 | Cri | 0.64 | 9.8 | 0.02 | Jun 1, 2022 | A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC20D), NAEOTOM Alpha (All VA40 versions < VA40 SP2), SOMATOM… | ||
| CVE-2022-29363 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. This vulnerability allows attackers to getshell via writing arbitrary files. | ||
| CVE-2020-23621 | Cri | 0.64 | 9.8 | 0.02 | May 2, 2022 | The Java Remote Management Interface of all versions of SVI MS Management System was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object. | ||
| CVE-2020-23620 | Cri | 0.64 | 9.8 | 0.02 | May 2, 2022 | The Java Remote Management Interface of all versions of Orlansoft ERP was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object. | ||
| CVE-2022-25767 | Cri | 0.64 | 9.8 | 0.03 | May 1, 2022 | All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets. |
- risk 0.64cvss 9.8epss 0.01
The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
- risk 0.64cvss 9.8epss 0.01
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
- risk 0.64cvss 9.8epss 0.01
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
- risk 0.64cvss 9.8epss 0.01
lesspipe before 2.06 allows attackers to execute code via Perl Storable (pst) files, because of deserialized object destructor execution via a key/value pair in a hash.
- risk 0.64cvss 8.8epss 0.83
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute arbitrary commands.
- risk 0.64cvss 9.8epss 0.02
OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.
- risk 0.64cvss 9.8epss 0.03
A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.17 and prior versions; Apache Dubbo 3.0.x version 3.0.11 and prior versions; Apache…
- risk 0.64cvss 9.8epss 0.01
Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php.
- risk 0.64cvss 9.8epss 0.01
dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 2 of 2).
- risk 0.64cvss 9.8epss 0.01
dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 1 of 2).
- risk 0.64cvss 9.8epss 0.01
Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
- risk 0.64cvss 9.8epss 0.04
The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server start-up or on a server…
- risk 0.64cvss 9.8epss 0.02
Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. Any user still on Java 8 who wishes to protect against deserialization attacks involving JMX or RMI should upgrade to Apache Geode…
- risk 0.64cvss 9.8epss 0.02
EasyUse MailHunter Ultimate’s cookie deserialization function has an inadequate validation vulnerability. Deserializing a cookie containing malicious payload will trigger this insecure deserialization vulnerability, allowing an unauthenticated remote attacker to execute…
- risk 0.64cvss 9.8epss 0.09
QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization.
- risk 0.64cvss 9.8epss 0.02
A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC20D), NAEOTOM Alpha (All VA40 versions < VA40 SP2), SOMATOM…
- risk 0.64cvss 9.8epss 0.01
Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. This vulnerability allows attackers to getshell via writing arbitrary files.
- risk 0.64cvss 9.8epss 0.02
The Java Remote Management Interface of all versions of SVI MS Management System was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object.
- risk 0.64cvss 9.8epss 0.02
The Java Remote Management Interface of all versions of Orlansoft ERP was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object.
- risk 0.64cvss 9.8epss 0.03
All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets.