Lucene search

K
cvelistRedhatCVELIST:CVE-2013-4521
HistoryFeb 06, 2020 - 3:43 p.m.

CVE-2013-4521

2020-02-0615:43:41
redhat
www.cve.org
1

9.7 High

AI Score

Confidence

High

0.1 Low

EPSS

Percentile

94.9%

RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data. NOTE: this vulnerability may overlap CVE-2013-2165.

CNA Affected

[
  {
    "product": "Nuxeo Platform",
    "vendor": "Nuxeo",
    "versions": [
      {
        "status": "affected",
        "version": "5.6.0 before HF27"
      },
      {
        "status": "affected",
        "version": "5.8.0 before HF-01"
      }
    ]
  }
]

9.7 High

AI Score

Confidence

High

0.1 Low

EPSS

Percentile

94.9%