Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25469
HistoryMay 21, 2020 - 3:52 a.m.

Remote Code Execution

2020-05-2103:52:01
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.922 High

EPSS

Percentile

99.0%

tomcat-catalina is vulnerable to remote code execution. If a remote attacker knows and is able to control the contents and name of a file, remote code execution can be achieved if the server is configured to use PersistenceManager with a FileStore and the PersistenceManager is configured with the default sessionAttributeValueClassNameFilter="null", through a request that results in the deserialization of the malicious file under the attacker’s control.

References