Lucene search

K

Synapse Security Vulnerabilities

cve
cve

CVE-2017-15708

In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) allows remote code execution attacks that can be performed by injecting specially crafted serialized objects...

9.8CVSS

9.7AI Score

0.026EPSS

2017-12-11 03:29 PM
168
2