PT-2017-13635 · Branagh · Ers Data System

West Shepherd

·

Publicado

2017-09-29

·

Atualizado

2020-07-29

·

CVE-2017-14702

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ERS Data System version 1.8.1.0
Description The issue allows remote attackers to execute arbitrary code. It is related to the deserialization of the com.branaghgroup.ecers.update.UpdateRequest object.
Recommendations For ERS Data System version 1.8.1.0, consider restricting the deserialization of the com.branaghgroup.ecers.update.UpdateRequest object to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-14702

Produtos afetados

Ers Data System