VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 39 of 156
  • CVE-2021-32098CriMay 7, 2021
    risk 0.64cvss 9.8epss 0.02

    Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.

  • CVE-2021-21426CriApr 21, 2021
    risk 0.64cvss 9.8epss 0.01

    Magento-lts is a long-term support alternative to Magento Community Edition (CE). In magento-lts versions 19.4.12 and prior and 20.0.8 and prior, there is a vulnerability caused by the unsecured deserialization of an object. A patch in versions 19.4.13 and 20.0.9 was back ported…

  • CVE-2021-21524CriApr 12, 2021
    risk 0.64cvss 9.8epss 0.03

    Dell SRM versions prior to 4.5.0.1 and Dell SMR versions prior to 4.5.0.1 contain an Untrusted Deserialization Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to arbitrary privileged code execution on the vulnerable…

  • CVE-2020-24914CriMar 4, 2021
    risk 0.64cvss 9.8epss 0.05

    A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileData" and allows an unauthenticated attacker to execute code via a crafted POST request.

  • CVE-2021-27335CriFeb 18, 2021
    risk 0.64cvss 9.8epss 0.03

    KollectApps before 4.8.16c is affected by insecure Java deserialization, leading to Remote Code Execution via a ysoserial.payloads.CommonsCollections parameter.

  • CVE-2021-22855CriFeb 17, 2021
    risk 0.64cvss 9.8epss 0.02

    The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can send malicious serialized objects to execute arbitrary commands.

  • CVE-2021-3160CriJan 28, 2021
    risk 0.64cvss 9.8epss 0.05

    Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product allows a remote attacker to inject unsecure serialized Java object using a specially crafted HTTP request, resulting in an unauthenticated remote code…

  • CVE-2020-4682CriJan 28, 2021
    risk 0.64cvss 9.8epss 0.08

    IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 186509.

  • CVE-2020-27583CriJan 26, 2021
    risk 0.64cvss 9.8epss 0.04

    IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unauthenticated attackers to execute arbitrary code. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

  • CVE-2020-24639CriJan 15, 2021
    risk 0.64cvss 9.8epss 0.07

    There is a vulnerability caused by unsafe Java deserialization that allows for arbitrary command execution in a containerized environment within Airwave Glass before 1.3.3. Successful exploitation can lead to complete compromise of the underlying host operating system.

  • CVE-2020-10658CriJan 6, 2021
    risk 0.64cvss 9.8epss 0.03

    The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's WriteImage API. The vulnerability allows an anonymous remote attacker to execute arbitrary code with local administrator privileges.…

  • CVE-2020-10656CriJan 6, 2021
    risk 0.64cvss 9.8epss 0.03

    The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's WriteWindowMouseWithChunksV2 API. The vulnerability allows an anonymous remote attacker to execute arbitrary code with local…

  • CVE-2020-10655CriJan 6, 2021
    risk 0.64cvss 9.8epss 0.03

    The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's WriteWindowMouse API. The vulnerability allows an anonymous remote attacker to execute arbitrary code with local administrator…

  • CVE-2020-11974CriDec 18, 2020
    risk 0.64cvss 9.8epss 0.08

    In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing mysql as database.

  • CVE-2020-22083CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.06

    jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been argued that this is expected and clearly documented behaviour. pickle is known to be capable of causing arbitrary code execution,…

  • CVE-2020-20136CriDec 14, 2020
    risk 0.64cvss 9.8epss 0.02

    QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to insecure configuration of TypeNameHandling property in Json.NET library.

  • CVE-2020-17531CriDec 8, 2020
    risk 0.64cvss 9.8epss 0.10

    A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, leading to deserialization without authentication. Apache Tapestry 4 reached end of life in 2008…

  • CVE-2020-5664CriNov 16, 2020
    risk 0.64cvss 9.8epss 0.03

    Deserialization of untrusted data vulnerability in XooNIps 3.49 and earlier allows remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2020-26867CriOct 12, 2020
    risk 0.64cvss 9.8epss 0.04

    ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server.

  • CVE-2020-25260CriSep 11, 2020
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows remote attackers to execute arbitrary code because of unsafe JSON deserialization.