Vulnerabilities > CVE-2020-23620 - Deserialization of Untrusted Data vulnerability in Orlansoft ERP
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
The Java Remote Management Interface of all versions of Orlansoft ERP was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |