VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 56 of 167
  • CVE-2023-33160HigJul 11, 2023
    risk 0.58cvss 8.8epss 0.04

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2022-36971HigMar 29, 2023
    risk 0.58cvss 8.8epss 0.15

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists…

  • CVE-2023-21706HigFeb 14, 2023
    risk 0.58cvss 8.8epss 0.04

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2022-1471HigDec 1, 2022
    risk 0.58cvss 8.3epss 1.00

    SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to…

  • CVE-2022-30287HigJul 28, 2022
    risk 0.58cvss 8.0epss 0.71

    Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deserialization of PHP objects.

  • CVE-2021-34992HigNov 15, 2021
    risk 0.58cvss 8.8epss 0.04

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS 6.10. Authentication is required to exploit this vulnerability. The specific flaw exists within Composite.dll. The issue results from the lack of proper validation…

  • CVE-2021-36981HigAug 31, 2021
    risk 0.58cvss 8.8epss 0.06

    In the server in SerNet verinice before 1.22.2, insecure Java deserialization allows remote authenticated attackers to execute arbitrary code.

  • CVE-2021-24579HigAug 30, 2021
    risk 0.58cvss 8.8epss 0.08

    The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unserialize() function without any validation or sanitisation, which could lead to a PHP Object Injection. Even though the plugin did not contain a suitable gadget to…

  • CVE-2021-25151HigApr 28, 2021
    risk 0.58cvss 8.8epss 0.12

    A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

  • CVE-2021-24066HigFeb 25, 2021
    risk 0.58cvss 8.8epss 0.06

    Microsoft SharePoint Remote Code Execution Vulnerability

  • CVE-2020-26118HigJan 11, 2021
    risk 0.58cvss 8.8epss 0.04

    In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialization vulnerability. The application's UpdateMemento class accepts a serialized Java object directly from the user without properly…

  • CVE-2020-8884HigJan 6, 2021
    risk 0.58cvss 8.8epss 0.04

    rcdsvc in the Proofpoint Insider Threat Management Windows Agent (formerly ObserveIT Windows Agent) before 7.9 allows remote authenticated users to execute arbitrary code as SYSTEM because of improper deserialization over named pipes.

  • CVE-2019-4728HigJan 5, 2021
    risk 0.58cvss 8.8epss 0.05

    IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By sending specially crafted request, an attacker…

  • CVE-2020-4521HigSep 15, 2020
    risk 0.58cvss 8.8epss 0.06

    IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization in Java. By sending specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary…

  • CVE-2020-4464HigJul 17, 2020
    risk 0.58cvss 8.8epss 0.13

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code on a system with a specially-crafted sequence of serialized objects over the SOAP connector. IBM X-Force ID: 181489.

  • CVE-2020-4305HigJul 9, 2020
    risk 0.58cvss 8.8epss 0.05

    IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this…

  • CVE-2020-9548CriMar 2, 2020
    risk 0.58cvss 9.8epss 0.19

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).

  • CVE-2020-9547CriMar 2, 2020
    risk 0.58cvss 9.8epss 0.18

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).

  • CVE-2019-14540CriSep 15, 2019
    risk 0.58cvss 9.8epss 0.11

    A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.

  • CVE-2019-11956HigJun 5, 2019
    risk 0.58cvss 8.8epss 0.06

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.