Vulnerabilities > Deserialization of Untrusted Data

DATE CVE VULNERABILITY TITLE RISK
2020-03-26 CVE-2020-10969 Deserialization of Untrusted Data vulnerability in multiple products
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
network
low complexity
fasterxml debian netapp oracle CWE-502
8.8
2020-03-26 CVE-2020-10968 Deserialization of Untrusted Data vulnerability in multiple products
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
network
low complexity
fasterxml debian netapp oracle CWE-502
8.8
2020-03-23 CVE-2020-6967 Deserialization of Untrusted Data vulnerability in Rockwellautomation Factorytalk Services Platform
In Rockwell Automation all versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platform, FactoryTalk Diagnostics exposes a .NET Remoting endpoint via RNADiagnosticsSrv.exe at TCPtcp/8082, which can insecurely deserialize untrusted data.
network
low complexity
rockwellautomation CWE-502
critical
9.8
2020-03-20 CVE-2020-7961 Deserialization of Untrusted Data vulnerability in Liferay Portal
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
network
low complexity
liferay CWE-502
critical
9.8
2020-03-17 CVE-2019-20453 Deserialization of Untrusted Data vulnerability in Pydio
A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4.
network
low complexity
pydio CWE-502
8.8
2020-03-17 CVE-2019-20452 Deserialization of Untrusted Data vulnerability in Pydio
A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4.
network
low complexity
pydio CWE-502
8.8
2020-03-11 CVE-2020-1947 Deserialization of Untrusted Data vulnerability in Apache Shardingsphere 4.0.0
In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load datasource configuration.
network
low complexity
apache CWE-502
critical
9.8
2020-03-10 CVE-2017-10992 Deserialization of Untrusted Data vulnerability in HP Storage Essentials 9.5.0.142
In HPE Storage Essentials 9.5.0.142, there is Unauthenticated Java Deserialization with remote code execution via OS commands in a request to invoker/JMXInvokerServlet, aka PSRT110461.
network
low complexity
hp CWE-502
critical
9.8
2020-03-09 CVE-2016-1487 Deserialization of Untrusted Data vulnerability in Lexmark Markvision Enterprise 2.1
Lexmark Markvision Enterprise before 2.3.0 misuses the Apache Commons Collections Library, leading to remote code execution because of Java deserialization.
network
low complexity
lexmark CWE-502
8.8
2020-03-09 CVE-2020-2158 Deserialization of Untrusted Data vulnerability in Jenkins Literate 0.1/0.2/1.0
Jenkins Literate Plugin 1.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
network
low complexity
jenkins CWE-502
8.8