VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 5 of 156
  • CVE-2017-5645CriApr 17, 2017
    risk 0.71cvss 9.8epss 0.89

    In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

  • CVE-2026-45659HigKEVMay 22, 2026
    risk 0.70cvss 8.8epss 0.10

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2025-32375CriApr 9, 2025
    risk 0.70cvss 9.8epss 0.50

    BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.8, there was an insecure deserialization in BentoML's runner server. By setting specific headers and parameters in the POST request, it is possible to execute…

  • CVE-2024-55556CriJan 7, 2025
    risk 0.70cvss 9.8epss 0.44

    A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote command execution on the server by manipulating the laravel_session cookie, exploiting arbitrary deserialization through the encrypted session data. The…

  • CVE-2024-22320CriFeb 2, 2024
    risk 0.70cvss 9.8epss 0.73

    IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code in the…

  • CVE-2023-44353CriNov 17, 2023
    risk 0.70cvss 9.8epss 0.80

    Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

  • CVE-2022-36974CriMar 29, 2023
    risk 0.70cvss 9.8epss 0.84

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists…

  • CVE-2021-30128CriApr 27, 2021
    risk 0.70cvss 9.8epss 0.81

    Apache OFBiz has unsafe deserialization prior to 17.12.07 version

  • CVE-2020-27868CriFeb 12, 2021
    risk 0.70cvss 9.8epss 0.81

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Qognify Ocularis 5.9.0.395. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of serialized objects provided to the…

  • CVE-2020-17144HigKEVDec 10, 2020
    risk 0.70cvss 8.4epss 0.37

    Microsoft Exchange Remote Code Execution Vulnerability

  • CVE-2020-10914CriApr 22, 2020
    risk 0.70cvss 9.8epss 0.47

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnerability. The specific flaw exists within the PerformHandshake method. The issue results from the…

  • CVE-2019-15271HigKEVNov 26, 2019
    risk 0.70cvss 8.8epss 0.06

    A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The attacker must have either a valid credential or an active session token.…

  • CVE-2019-11945CriJun 5, 2019
    risk 0.70cvss 9.8epss 0.79

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-9875HigKEVMay 31, 2019
    risk 0.70cvss 8.8epss 0.14

    Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter.

  • CVE-2019-0192CriMar 7, 2019
    risk 0.70cvss 9.8epss 0.78

    In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on…

  • CVE-2015-7501CriNov 9, 2017
    risk 0.70cvss 9.8epss 0.83

    Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform…

  • CVE-2025-40553CriJan 28, 2026
    risk 0.69cvss 9.8epss 0.60

    SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

  • CVE-2025-20124CriFeb 5, 2025
    risk 0.69cvss 9.9epss 0.18

    A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands as the root user on an affected device. This vulnerability is due to insecure deserialization of user-supplied Java byte streams by the affected software. An…

  • CVE-2024-38094HigKEVJul 9, 2024
    risk 0.69cvss 7.2epss 0.51

    Microsoft SharePoint Remote Code Execution Vulnerability

  • CVE-2024-20953HigKEVFeb 17, 2024
    risk 0.69cvss 8.8epss 0.03

    Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful…