VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,308)

page 38 of 166
  • CVE-2022-45378CriNov 14, 2022
    risk 0.64cvss 9.8epss 0.02

    In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the classpath that meet certain criteria. Depending on what classes are available on the classpath this might even…

  • CVE-2022-38652CriNov 12, 2022
    risk 0.64cvss 9.9epss 0.01

    A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerability enables a malicious authenticated user to run arbitrary code or malware within a Hyperic Agent instance and its host operating system with the privileges of…

  • CVE-2022-44562CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.

  • CVE-2022-44559CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.

  • CVE-2022-44558CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.

  • CVE-2022-44542CriNov 1, 2022
    risk 0.64cvss 9.8epss 0.01

    lesspipe before 2.06 allows attackers to execute code via Perl Storable (pst) files, because of deserialized object destructor execution via a key/value pair in a hash.

  • CVE-2022-36958HigOct 20, 2022
    risk 0.64cvss 8.8epss 0.83

    SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute arbitrary commands.

  • CVE-2022-43019CriOct 19, 2022
    risk 0.64cvss 9.8epss 0.02

    OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.

  • CVE-2022-39198CriOct 18, 2022
    risk 0.64cvss 9.8epss 0.03

    A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.17 and prior versions; Apache Dubbo 3.0.x version 3.0.11 and prior versions; Apache…

  • CVE-2022-40889CriOct 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php.

  • CVE-2018-18447CriOct 12, 2022
    risk 0.64cvss 9.8epss 0.01

    dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 2 of 2).

  • CVE-2018-18446CriOct 12, 2022
    risk 0.64cvss 9.8epss 0.01

    dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 1 of 2).

  • CVE-2022-41237CriSep 21, 2022
    risk 0.64cvss 9.8epss 0.02

    Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

  • CVE-2022-29063CriSep 2, 2022
    risk 0.64cvss 9.8epss 0.05

    The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server start-up or on a server…

  • CVE-2022-37021CriAug 31, 2022
    risk 0.64cvss 9.8epss 0.03

    Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. Any user still on Java 8 who wishes to protect against deserialization attacks involving JMX or RMI should upgrade to Apache Geode…

  • CVE-2022-35223CriAug 2, 2022
    risk 0.64cvss 9.8epss 0.02

    EasyUse MailHunter Ultimate’s cookie deserialization function has an inadequate validation vulnerability. Deserializing a cookie containing malicious payload will trigger this insecure deserialization vulnerability, allowing an unauthenticated remote attacker to execute…

  • CVE-2021-41419CriJul 18, 2022
    risk 0.64cvss 9.8epss 0.09

    QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization.

  • CVE-2022-29875CriJun 1, 2022
    risk 0.64cvss 9.8epss 0.02

    A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC20D), NAEOTOM Alpha (All VA40 versions < VA40 SP2), SOMATOM…

  • CVE-2022-29363CriMay 12, 2022
    risk 0.64cvss 9.8epss 0.01

    Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. This vulnerability allows attackers to getshell via writing arbitrary files.

  • CVE-2020-23621CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.02

    The Java Remote Management Interface of all versions of SVI MS Management System was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object.