Vulnerability index

Browse CVEs

207 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Superset CRITICAL 9.8
CVE-2018-8021EPSS 53%

Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. …

Fix: 0.23+
Fix from $2,300 2018-11-07
Ignite CRITICAL 9.8
CVE-2018-8018EPSS 7%

In Apache Ignite before 2.4.8 and 2.5.x before 2.5.3, the serialization mechanism does not have a list of classes allowed for serialization/deseriali…

Fix: 2.4.8 / 2.5.3+
Fix from $2,300 2018-07-20
Batik CRITICAL 9.8
CVE-2018-8013EPSS 19%

In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name w…

Fix: 1.10 / 7.2+
Fix from $2,300 2018-05-24
Nifi HIGH 7.5
CVE-2018-1310

Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial of service. See ActiveMQ CVE…

Fix: 1.6.0+
Fix from $1,950 2018-05-23
Ignite CRITICAL 9.8
CVE-2018-1295EPSS 6%

In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes i…

Fix: after 2.3.0
Fix from $2,300 2018-04-02
Geode CRITICAL 9.8
CVE-2017-15692

In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains acce…

Fix: 1.4.0+
Fix from $2,300 2018-02-27
Geode HIGH 7.5
CVE-2017-15693

In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocations cause t…

Fix: 1.4.0+
Fix from $1,950 2018-02-27
Nifi MEDIUM 5.0
CVE-2017-15703

Any authenticated user (valid client certificate but without ACL permissions) could upload a template which contained malicious code and caused a den…

Fix: after 1.4.0
Fix from $1,600 2018-01-25
Groovy CRITICAL 9.8
CVE-2016-6814EPSS 17%

When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java se…

Fix: after 2.4.7
Fix from $2,300 2018-01-18
Flex Blazeds CRITICAL 9.8
CVE-2017-5641EPSS 21%

Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object deserialization by default. …

Fix: 8.5.3-00+
Fix from $2,300 2017-12-28
Camel CRITICAL 9.8
CVE-2017-12633EPSS 7%

The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. D…

Fix: 2.19.4 / 2.20.1+
Fix from $2,300 2017-11-15
Camel CRITICAL 9.8
CVE-2017-12634EPSS 7%

The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De…

Fix: 2.19.4+
Fix from $2,300 2017-11-15
Ws Xmlrpc CRITICAL 9.8
CVE-2016-5003EPSS 15%

The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serializ…

No fix yet
Fix from $2,300 2017-10-27
James Server HIGH 7.8
CVE-2017-12628

The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to ex…

Fix: after 3.0.0
Fix from $1,950 2017-10-20
Openmeetings CRITICAL 9.8
CVE-2016-8736

Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.

Fix: 3.1.2+
Fix from $2,300 2017-10-12
Struts HIGH 8.1
CVE-2017-9805 KEVEPSS 99%

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for des…

Fix: 2.3.34 / 2.5.13+
Fix from $1,950 2017-09-15
Brooklyn HIGH 8.8
CVE-2016-8744

Apache Brooklyn uses the SnakeYAML library for parsing YAML inputs. SnakeYAML allows the use of YAML tags to indicate that SnakeYAML should unmarshal…

Fix: after 0.9.0
Fix from $1,950 2017-09-13
Spark HIGH 7.8
CVE-2017-12612

In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by its socket. This makes applications launched …

Mitigation only
Fix from $1,950 2017-09-13
Wicket CRITICAL 9.1
CVE-2016-6793EPSS 8%

The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop…

Fix: 1.5.17 / 6.25.0+
Fix from $2,300 2017-07-17
Log4j CRITICAL 9.8
CVE-2017-5645EPSS 90%

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a …

Fix: 2.8.2+
Fix from $2,300 2017-04-17
Tomee CRITICAL 9.8
CVE-2016-0779EPSS 10%

The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted s…

Fix: after 1.7.3
Fix from $2,300 2017-04-11
Nutch CRITICAL 9.8
CVE-2016-6809EPSS 8%

Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to d…

Fix: after 1.13
Fix from $2,300 2017-04-06
Camel CRITICAL 9.8
CVE-2016-8749EPSS 11%

Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.

No fix yet
Fix from $2,300 2017-03-28
Camel CRITICAL 9.8
CVE-2017-3159EPSS 6%

Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to secur…

Fix: after 2.18.1
Fix from $2,300 2017-03-07
Myfaces Trinidad CRITICAL 9.8
CVE-2016-5019EPSS 8%

CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow…

Fix: 1.0.13 / 1.2.15+
Fix from $2,300 2016-10-03
Artemis HIGH 7.2
CVE-2016-4978EPSS 7%

The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache Ac…

Fix: 1.4.0+
Fix from $1,950 2016-09-27
Commons Collections CRITICAL 9.8
CVE-2015-6420EPSS 18%

Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and…

Fix: 3.2.2+
Fix from $2,300 2015-12-15