Vulnerabilities > Graniteds > Graniteds

DATE CVE VULNERABILITY TITLE RISK
2018-06-11 CVE-2017-3200 Deserialization of Untrusted Data vulnerability in Graniteds 3.1.1
The Java implementation of AMF3 deserializers used in GraniteDS, version 3.1.1.G, may allow instantiation of arbitrary classes via their public parameter-less constructor and subsequently call arbitrary Java Beans setter methods.
network
graniteds CWE-502
6.8
2018-06-11 CVE-2017-3199 Deserialization of Untrusted Data vulnerability in Graniteds 3.1.1
The Java implementation of GraniteDS, version 3.1.1.GA, AMF3 deserializers derives class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExternalizable.
network
graniteds CWE-502
6.8