VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 7 of 156
  • CVE-2018-15691CriAug 30, 2018
    risk 0.68cvss 9.8epss 0.17

    Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute arbitrary code.

  • CVE-2018-9843CriApr 12, 2018
    risk 0.68cvss 9.8epss 0.17

    The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute arbitrary code via a serialized .NET object in an Authorization HTTP header.

  • CVE-2017-17672CriDec 14, 2017
    risk 0.68cvss 9.8epss 0.15

    In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circumstances, code execution, because of unsafe usage of PHP's unserialize() in vB_Library_Template's cacheTemplates() function, which…

  • CVE-2017-11153CriAug 8, 2017
    risk 0.68cvss 9.8epss 0.12

    Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain administrator privileges via a crafted serialized payload.

  • CVE-2024-28988CriSep 1, 2025
    risk 0.67cvss 9.8epss 0.39

    SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability was found by the ZDI team after researching a previous…

  • CVE-2025-49533CriJul 8, 2025
    risk 0.67cvss 9.8epss 0.47

    Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction. Scope is unchanged.

  • CVE-2024-2044CriMar 7, 2024
    risk 0.67cvss 9.9epss 0.79

    pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, an unauthenticated attacker can load and deserialize remote pickle objects and gain code execution. If the server…

  • CVE-2023-49442CriJan 3, 2024
    risk 0.67cvss 9.8epss 0.39

    Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.

  • CVE-2022-33318CriJul 20, 2022
    risk 0.67cvss 9.8epss 0.45

    Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97 to 10.97.1, Mitsubishi Electric Iconics…

  • CVE-2022-24082CriJul 19, 2022
    risk 0.67cvss 9.8epss 0.12

    If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized payloads to attack the underlying system. This does not affect…

  • CVE-2022-23450CriApr 12, 2022
    risk 0.67cvss 9.8epss 0.36

    A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). The affected system allows remote users to send maliciously crafted objects. Due to insecure deserialization of…

  • CVE-2021-25274CriFeb 3, 2021
    risk 0.67cvss 9.8epss 0.36

    The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauthenticated clients can send messages to TCP port 1801 that the Collector Service will process.…

  • CVE-2020-8165CriJun 19, 2020
    risk 0.67cvss 9.8epss 0.46

    A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.

  • CVE-2019-8662CriDec 18, 2019
    risk 0.67cvss 9.8epss 0.10

    This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. An attacker may be able to trigger a use-after-free in an application deserializing an untrusted NSDictionary.

  • CVE-2019-16891CriOct 4, 2019
    risk 0.67cvss 9.8epss 0.46

    Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.

  • CVE-2019-16894CriSep 26, 2019
    risk 0.67cvss 9.8epss 0.03

    download.php in inoERP 4.15 allows SQL injection through insecure deserialization.

  • CVE-2018-15133HigKEVAug 9, 2018
    risk 0.67cvss 8.1epss 0.77

    In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method in Illuminate/Encryption/Encrypter.php and PendingBroadcast in…

  • CVE-2017-12558CriFeb 15, 2018
    risk 0.67cvss 9.8epss 0.38

    A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.

  • CVE-2017-12556CriFeb 15, 2018
    risk 0.67cvss 9.8epss 0.38

    A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.

  • CVE-2017-11284CriDec 1, 2017
    risk 0.67cvss 9.8epss 0.43

    Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.