PT-2021-15228 · Unknown · Soar Cloud System

Tsungshu Chiu

·

Published

2021-02-17

·

Updated

2021-02-24

·

CVE-2021-22855

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Soar Cloud System (affected versions not specified)
Description The issue concerns the HR Portal of the Soar Cloud System, where a specific function accepts any type of object to be deserialized. This allows attackers to send malicious serialized objects, potentially leading to the execution of arbitrary commands.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-22855

Affected Products

Soar Cloud System