PT-2021-14554 · Unknown · Knowledge Management

Published

2021-03-09

·

Updated

2021-03-17

·

CVE-2021-21488

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50
Description The issue allows a remote attacker with basic privileges to deserialize user-controlled data without verification, leading to insecure deserialization. This triggers the attacker's code and impacts Availability.
Recommendations For versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50, consider restricting access to user-controlled data deserialization to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-21488

Affected Products

Knowledge Management