Vulnerability index

Browse CVEs

207 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Dubbo CRITICAL 9.8
CVE-2022-39198

A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This iss…

Fix: after 3.0.11
Fix from $2,300 2022-10-18
Inlong HIGH 8.8
CVE-2022-40955

In versions of Apache InLong prior to 1.3.0, an attacker with sufficient privileges to specify MySQL JDBC connection URL parameters and to write arbi…

Fix: 1.3.0+
Fix from $1,950 2022-09-20
Ofbiz CRITICAL 9.8
CVE-2022-29063

The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier…

Fix: 18.12.06+
Fix from $2,300 2022-09-02
Geode CRITICAL 9.8
CVE-2022-37021

Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. A…

Fix: after 1.13.4
Fix from $2,300 2022-08-31
Geode HIGH 8.8
CVE-2022-37022

Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 11. Any user…

Fix: after 1.13.2
Fix from $1,950 2022-08-31
Geode MEDIUM 6.5
CVE-2022-37023

Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data flaw when using REST API on Java 8 or Java 11. Any user w…

Fix: 1.15.0+
Fix from $1,600 2022-08-31
Hadoop HIGH 8.8
CVE-2021-25642

ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation…

Fix: 2.10.2 / 3.2.4+
Fix from $1,950 2022-08-25
Cayenne HIGH 8.8
CVE-2022-24289

Hessian serialization is a network protocol that supports object-based transmission. Apache Cayenne's optional Remote Object Persistence (ROP) featur…

Fix: 4.2+
Fix from $1,950 2022-02-11
Karaf HIGH 8.1
CVE-2021-41766

Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology…

Fix: 4.3.6+
Fix from $1,950 2022-01-26
Log4j HIGH 8.8
CVE-2022-23302EPSS 64%

JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration…

Fix: 1.2.18.1+
Fix from $1,950 2022-01-18
Chainsaw HIGH 8.8
CVE-2022-23307EPSS 54%

CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j…

Fix: 1.2.18.1 / 2.0+
Fix from $1,950 2022-01-18
Dubbo CRITICAL 9.8
CVE-2021-43297EPSS 17%

A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dub…

Fix: 2.6.12 / 2.7.15+
Fix from $2,300 2022-01-10
Log4j HIGH 7.5
CVE-2021-4104EPSS 81%

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attack…

Patch available
Fix from $1,950 2021-12-14
Log4j CRITICAL 10.0
CVE-2021-44228 KEVEPSS 100%

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and…

Fix: 2.1.0 / 2.3.1+
Fix from $2,300 2021-12-10
Shardingsphere Ui HIGH 7.5
CVE-2021-26558

Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link resources. This issue affects Apa…

Fix: 5.0.0+
Fix from $1,950 2021-11-11
Storm CRITICAL 9.8
CVE-2021-40865EPSS 66%

An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (…

Fix: 1.2.4 / 2.1.1+
Fix from $2,300 2021-10-25
Ddlutils CRITICAL 9.8
CVE-2021-41616

Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINAR…

Mitigation only
Fix from $2,300 2021-09-30
Dubbo CRITICAL 9.8
CVE-2021-37579EPSS 7%

The Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the configuration set by the server.…

Fix: 2.7.13 / 3.0.2+
Fix from $2,300 2021-09-09
Dubbo CRITICAL 9.8
CVE-2021-36163

In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST reque…

Fix: after 3.0.1
Fix from $2,300 2021-09-07
Juddi CRITICAL 9.8
CVE-2021-37578

Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provides an alternate transport fo…

Fix: 3.3.10+
Fix from $2,300 2021-07-29
Chainsaw CRITICAL 9.8
CVE-2020-9493

A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution.

Fix: 1.2.18.1 / 2.0+
Fix from $2,300 2021-06-16
Dubbo CRITICAL 9.8
CVE-2021-25641EPSS 21%

Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. But for Dubbo versions before…

Fix: 2.6.9 / 2.7.8+
Fix from $2,300 2021-06-01
Dubbo CRITICAL 9.8
CVE-2021-30179

Apache Dubbo prior to 2.6.9 and 2.7.9 by default supports generic calls to arbitrary methods exposed by provider interfaces. These invocations are ha…

Fix: 2.6.9 / 2.7.10+
Fix from $2,300 2021-06-01
Ofbiz CRITICAL 9.8
CVE-2021-29200EPSS 55%

Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack

Fix: 17.12.07+
Fix from $2,300 2021-04-27
Ofbiz CRITICAL 9.8
CVE-2021-30128EPSS 81%

Apache OFBiz has unsafe deserialization prior to 17.12.07 version

Fix: 17.12.07+
Fix from $2,300 2021-04-27
Tapestry CRITICAL 9.8
CVE-2021-27850EPSS 94%

A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5,…

Fix: 5.6.2 / 5.7.1+
Fix from $2,300 2021-04-15
Activemq CRITICAL 9.8
CVE-2021-21347EPSS 14%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.8
CVE-2021-21350EPSS 15%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.1
CVE-2021-21351EPSS 82%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote a…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq HIGH 8.6
CVE-2021-21349EPSS 47%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $1,950 2021-03-23