Lucene search

K
nvd[email protected]NVD:CVE-2013-4521
HistoryFeb 06, 2020 - 4:15 p.m.

CVE-2013-4521

2020-02-0616:15:11
CWE-502
web.nvd.nist.gov
1

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.7 High

AI Score

Confidence

High

0.1 Low

EPSS

Percentile

94.9%

RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data. NOTE: this vulnerability may overlap CVE-2013-2165.

Affected configurations

NVD
Node
nuxeonuxeoMatch5.6.0-
OR
nuxeonuxeoMatch5.6.0hotfix01
OR
nuxeonuxeoMatch5.6.0hotfix02
OR
nuxeonuxeoMatch5.6.0hotfix03
OR
nuxeonuxeoMatch5.6.0hotfix04
OR
nuxeonuxeoMatch5.6.0hotfix05
OR
nuxeonuxeoMatch5.6.0hotfix06
OR
nuxeonuxeoMatch5.6.0hotfix07
OR
nuxeonuxeoMatch5.6.0hotfix08
OR
nuxeonuxeoMatch5.6.0hotfix09
OR
nuxeonuxeoMatch5.6.0hotfix10
OR
nuxeonuxeoMatch5.6.0hotfix11
OR
nuxeonuxeoMatch5.6.0hotfix12
OR
nuxeonuxeoMatch5.6.0hotfix13
OR
nuxeonuxeoMatch5.6.0hotfix14
OR
nuxeonuxeoMatch5.6.0hotfix15
OR
nuxeonuxeoMatch5.6.0hotfix16
OR
nuxeonuxeoMatch5.6.0hotfix17
OR
nuxeonuxeoMatch5.6.0hotfix18
OR
nuxeonuxeoMatch5.6.0hotfix19
OR
nuxeonuxeoMatch5.6.0hotfix20
OR
nuxeonuxeoMatch5.6.0hotfix21
OR
nuxeonuxeoMatch5.6.0hotfix22
OR
nuxeonuxeoMatch5.6.0hotfix23
OR
nuxeonuxeoMatch5.6.0hotfix24
OR
nuxeonuxeoMatch5.6.0hotfix25
OR
nuxeonuxeoMatch5.6.0hotfix26
OR
nuxeonuxeoMatch5.8.0-

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.7 High

AI Score

Confidence

High

0.1 Low

EPSS

Percentile

94.9%