PT-2017-19204 · Apache+1 · Apache Commons+1
Erik Bosman
·
Publicado
2017-06-27
·
Atualizado
2019-08-03
·
CVE-2017-9830
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Code42 CrashPlan version 5.4.x
Description
The issue allows for Remote Code Execution in the affected software via the org.apache.commons.ssl.rmi.DateRMI Java class. Upon instantiation, this class creates an RMI server that listens on a TCP port and deserializes objects sent by TCP clients.
Recommendations
For Code42 CrashPlan version 5.4.x, consider disabling the use of the org.apache.commons.ssl.rmi.DateRMI Java class until a patch is available to prevent Remote Code Execution. Restrict access to the RMI server to minimize the risk of exploitation.
Correção
Deserialization of Untrusted Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Commons
Code42 Crashplan