Vulnerabilities > Graniteds

DATE CVE VULNERABILITY TITLE RISK
2018-06-11 CVE-2017-3200 Deserialization of Untrusted Data vulnerability in Graniteds 3.1.1
The Java implementation of AMF3 deserializers used in GraniteDS, version 3.1.1.G, may allow instantiation of arbitrary classes via their public parameter-less constructor and subsequently call arbitrary Java Beans setter methods.
network
graniteds CWE-502
6.8
2018-06-11 CVE-2017-3199 Deserialization of Untrusted Data vulnerability in Graniteds 3.1.1
The Java implementation of GraniteDS, version 3.1.1.GA, AMF3 deserializers derives class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExternalizable.
network
graniteds CWE-502
6.8
2016-03-25 CVE-2016-2340 XML External Entity Information Disclosure vulnerability in Graniteds Granite Data Services 3.1.1Snapshot
The AMF framework in Granite Data Services 3.1.1-SNAPSHOT allows remote authenticated users to read arbitrary files, send TCP requests to intranet servers, or cause a denial of service via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
network
low complexity
graniteds
5.5