PT-2017-19204 · Apache+1 · Apache Commons+1
Erik Bosman
·
Published
2017-06-27
·
Updated
2019-08-03
·
CVE-2017-9830
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Code42 CrashPlan version 5.4.x
Description
The issue allows for Remote Code Execution in the affected software via the org.apache.commons.ssl.rmi.DateRMI Java class. Upon instantiation, this class creates an RMI server that listens on a TCP port and deserializes objects sent by TCP clients.
Recommendations
For Code42 CrashPlan version 5.4.x, consider disabling the use of the org.apache.commons.ssl.rmi.DateRMI Java class until a patch is available to prevent Remote Code Execution. Restrict access to the RMI server to minimize the risk of exploitation.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Commons
Code42 Crashplan