Vulnerabilities > Graniteds
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-06-11 | CVE-2017-3200 | Deserialization of Untrusted Data vulnerability in Graniteds 3.1.1 The Java implementation of AMF3 deserializers used in GraniteDS, version 3.1.1.G, may allow instantiation of arbitrary classes via their public parameter-less constructor and subsequently call arbitrary Java Beans setter methods. | 8.1 |
2018-06-11 | CVE-2017-3199 | Deserialization of Untrusted Data vulnerability in Graniteds 3.1.1 The Java implementation of GraniteDS, version 3.1.1.GA, AMF3 deserializers derives class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExternalizable. | 8.1 |
2016-03-25 | CVE-2016-2340 | Unspecified vulnerability in Graniteds Granite Data Services 3.1.1Snapshot The AMF framework in Granite Data Services 3.1.1-SNAPSHOT allows remote authenticated users to read arbitrary files, send TCP requests to intranet servers, or cause a denial of service via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | 5.4 |