Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3853
HistoryApr 06, 2017 - 8:05 a.m.

Remote Code Execution (RCE)

2017-04-0608:05:24
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
35

0.098 Low

EPSS

Percentile

94.9%

flex-messenger-core is vulnerable to remote code execution (RCE). The AMF3 deserializers in the library allows the instantiation of arbitrary classes via parameter-less java beans constructors. This allows a malicious user to send a malicious AMF3 object to the system to execute arbitrary code.