Vulnerabilities > CVE-2020-26118 - Deserialization of Untrusted Data vulnerability in Smartbear Collaborator

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
smartbear
CWE-502

Summary

In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialization vulnerability. The application's UpdateMemento class accepts a serialized Java object directly from the user without properly sanitizing it. A malicious object can be submitted to the server via an authenticated attacker to execute commands on the underlying system.

Vulnerable Configurations

Part Description Count
Application
Smartbear
307

Common Weakness Enumeration (CWE)