VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 4 of 156
  • CVE-2020-10915CriApr 22, 2020
    risk 0.74cvss 9.8epss 0.87

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HandshakeResult method. The issue results from the lack…

  • CVE-2018-3245CriOct 17, 2018
    risk 0.74cvss 9.8epss 0.94

    Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access…

  • CVE-2025-53690CriKEVSep 3, 2025
    risk 0.73cvss 9.0epss 0.31

    Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.

  • CVE-2024-2054CriMar 21, 2024
    risk 0.73cvss 9.8epss 0.81

    The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user.

  • CVE-2019-4279CriMay 17, 2019
    risk 0.73cvss 9.8epss 0.80

    IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 160445.

  • CVE-2019-7214CriApr 24, 2019
    risk 0.73cvss 9.8epss 0.85

    SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely accessible. This port is not accessible remotely by default after applying the Build 6985 patch.

  • CVE-2017-12557CriFeb 15, 2018
    risk 0.73cvss 9.8epss 0.80

    A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.

  • CVE-2023-21839HigKEVJan 18, 2023
    risk 0.72cvss 7.5epss 1.00

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP…

  • CVE-2017-5941CriFeb 9, 2017
    risk 0.72cvss 9.8epss 0.61

    An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE).

  • CVE-2012-0911CriJul 12, 2012
    risk 0.72cvss 9.8epss 0.63

    TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1) cookieName to lib/banners/bannerlib.php; (2) printpages or (3) printstructures parameter to (a) tiki-print_multi_pages.php or (b)…

  • CVE-2025-0994HigKEVFeb 6, 2025
    risk 0.71cvss 8.8epss 0.31

    Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet…

  • CVE-2024-1800CriMar 20, 2024
    risk 0.71cvss 9.9epss 0.40

    In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vulnerability.

  • CVE-2024-23759CriFeb 12, 2024
    risk 0.71cvss 9.8epss 0.48

    Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function.

  • CVE-2023-1133CriMar 27, 2023
    risk 0.71cvss 9.8epss 0.50

    Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated…

  • CVE-2021-39144HigKEVAug 23, 2021
    risk 0.71cvss 8.5epss 0.98

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed…

  • CVE-2021-31474CriMay 21, 2021
    risk 0.71cvss 9.8epss 0.94

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SolarWinds.Serialization library.…

  • CVE-2021-3287CriApr 22, 2021
    risk 0.71cvss 9.8epss 0.51

    Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class.

  • CVE-2019-10173CriJul 23, 2019
    risk 0.71cvss 9.8epss 0.95

    It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported…

  • CVE-2019-5434CriMay 6, 2019
    risk 0.71cvss 9.8epss 0.57

    An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in the "openads.spc" RPC method. Such vulnerability could be used to perform various types of attacks, e.g. exploit serialize-related…

  • CVE-2018-15381CriNov 8, 2018
    risk 0.71cvss 9.8epss 0.87

    A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user. The vulnerability is due to insecure deserialization of user-supplied content by the…