Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38005
HistoryNov 15, 2022 - 8:45 a.m.

Deserialization Of Untrusted Data

2022-11-1508:45:59
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17
deserialization
untrusted data
arbitrary code
rpcrouterservlet
vulnerability
software

0.007 Low

EPSS

Percentile

80.8%

soap is vulnerable to untrusted data deserialization. The vulnerability exists due to lack of authentication in RPCRouterServlet which allows an attacker to execute arbitrary code in to the system.

CPENameOperatorVersion
soaple2.3.1
soaple2.3.1