CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,137 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 2 of 63
- CVE-2016-8648HIGHCVSS 7.2EG 7.22018-08-01
It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX operations. An attacker could use this flaw to execute remote code on the server as the user ru…
- CVE-2016-8653MEDIUMCVSS 5.3EG 5.32018-08-01
It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this flaw to launch a denial of service attack.
- CVE-2016-8736CRITICALCVSS 9.8EG 9.82017-10-12
Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.
- CVE-2016-8744HIGHCVSS 8.8EG 8.82017-09-13
Apache Brooklyn uses the SnakeYAML library for parsing YAML inputs. SnakeYAML allows the use of YAML tags to indicate that SnakeYAML should unmarshal data to a Java type. In the default configuration in Brooklyn before 0.10.0, SnakeYAML wi…
- CVE-2016-8749CRITICALCVSS 9.8EG 9.82017-03-28
Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.
- CVE-2016-9045HIGHCVSS 8.8EG 8.82018-09-17
A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker can send a crafted web …
- CVE-2016-9483CRITICALCVSS 9.8EG 9.82018-07-13
The PHP form code generated by PHP FormMail Generator deserializes untrusted input as part of the phpfmg_filman_download() function. A remote unauthenticated attacker may be able to use this vulnerability to inject PHP code, or along with …
- CVE-2016-9498CRITICALCVSS 9.8EG 9.82018-07-13
ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by remote user without authentication and it allows to execute remote code compromising the a…
- CVE-2016-9585MEDIUMCVSS 5.3EG 5.32018-03-09
Red Hat JBoss EAP version 5 is vulnerable to a deserialization of untrusted data in the JMX endpoint when deserializes the credentials passed to it. An attacker could exploit this vulnerability resulting in a denial of service attack.
- CVE-2016-9865CRITICALCVSS 9.8EG 9.82016-12-11
An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), …
- CVE-2017-0806HIGHCVSS 7.8EG 7.82017-10-04
An elevation of privilege vulnerability in the Android framework (gatekeeperresponse). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62998805.
- CVE-2017-0903CRITICALCVSS 9.8EG 9.82017-10-11
RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used…
- CVE-2017-1000034HIGHCVSS 8.1EG 8.12017-07-17
Akka versions <=2.4.16 and 2.5-M1 are vulnerable to a java deserialization attack in its Remoting component resulting in remote code execution in the context of the ActorSystem.
- CVE-2017-1000053HIGHCVSS 8.1EG 8.12017-07-17
Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to arbitrary code execution in the deserialization functions of Plug.Session.
- CVE-2017-1000148HIGHCVSS 8.8EG 8.82017-11-03
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to PHP code execution as Mahara would pass portions of the XML through the PHP "unserialize()" function when importing a skin from an XML file.
- CVE-2017-1000195HIGHCVSS 7.5EG 7.52017-11-17
October CMS build 412 is vulnerable to PHP object injection in asset move functionality resulting in ability to delete files limited by file permissions on the server.
- CVE-2017-1000207HIGHCVSS 8.8EG 8.82017-11-27
A vulnerability in Swagger-Parser's version <= 1.0.30 and Swagger codegen version <= 2.2.2 yaml parsing functionality results in arbitrary code being executed when a maliciously crafted yaml Open-API specification is parsed. This in partic…
- CVE-2017-1000208HIGHCVSS 8.8EG 8.82017-11-17
A vulnerability in Swagger-Parser's (version <= 1.0.30) yaml parsing functionality results in arbitrary code being executed when a maliciously crafted yaml Open-API specification is parsed. This in particular, affects the 'generate' and 'v…
- CVE-2017-1000248CRITICALCVSS 9.8EG 9.82017-11-17
Redis-store <=v1.3.0 allows unsafe objects to be loaded from redis
- CVE-2017-1000353CRITICALCVSS 9.8EG 9.8⚠ KEV2018-01-29
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java `SignedO…
- CVE-2017-1000355MEDIUMCVSS 6.5EG 6.52018-01-29
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an XStream: Java crash when trying to instantiate void/Void.
- CVE-2017-10803MEDIUMCVSS 6.5EG 6.52017-07-04
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Database Anonymization module allows remote authenticated privileged users to execute arbitrary Pyth…
- CVE-2017-10932CRITICALCVSS 9.8EG 9.82017-09-28
All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, NR8000 TR and NR8950 are the applications of C/S architecture using the Java RMI service in which the servers use the Ap…
- CVE-2017-10934CRITICALCVSS 9.8EG 9.82018-07-25
All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Collections (ACC) library that may result in Java deserialization vulnerabilities. An unauthenticated re…
- CVE-2017-10992CRITICALCVSS 9.8EG 9.82020-03-10
In HPE Storage Essentials 9.5.0.142, there is Unauthenticated Java Deserialization with remote code execution via OS commands in a request to invoker/JMXInvokerServlet, aka PSRT110461.
- CVE-2017-11143HIGHCVSS 7.5EG 7.52017-07-10
In PHP before 5.6.31, an invalid free in the WDDX deserialization of boolean parameters could be used by attackers able to inject XML for deserialization to crash the PHP interpreter, related to an invalid free for an empty boolean element…
- CVE-2017-11153CRITICALCVSS 9.8EG 9.82017-08-08
Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain administrator privileges via a crafted serialized payload.
- CVE-2017-11283CRITICALCVSS 9.8EG 9.82017-12-01
Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.
- CVE-2017-11284CRITICALCVSS 9.8EG 9.82017-12-01
Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.
- CVE-2017-12149CRITICALCVSS 9.8EG 9.8⚠ KEV2017-10-04
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization …
- CVE-2017-12556CRITICALCVSS 9.8EG 9.82018-02-15
A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.
- CVE-2017-12557CRITICALCVSS 9.8EG 9.82018-02-15
A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.
- CVE-2017-12558CRITICALCVSS 9.8EG 9.82018-02-15
A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.
- CVE-2017-12612HIGHCVSS 7.8EG 7.82017-09-13
In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by its socket. This makes applications launched programmatically using the launcher API potentially vulnerable to arbitrary code execution…
- CVE-2017-12628HIGHCVSS 7.8EG 7.82017-10-20
The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to execute arbitrary commands. As James exposes JMX socket by default only on local-host, this …
- CVE-2017-12633CRITICALCVSS 9.8EG 9.82017-11-15
The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
- CVE-2017-12634CRITICALCVSS 9.8EG 9.82017-11-15
The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
- CVE-2017-12796CRITICALCVSS 9.8EG 9.82017-10-23
The Reporting Compatibility Add On before 2.0.4 for OpenMRS, as distributed in OpenMRS Reference Application before 2.6.1, does not authenticate users when deserializing XML input into ReportSchema objects. The result is that remote unauth…
- CVE-2017-13286HIGHCVSS 7.8EG 7.82018-04-04
In writeToParcel and readFromParcel of OutputConfiguration.java, there is a permission bypass due to mismatched serialization. This could lead to a local escalation of privilege where the user can start an activity with system privileges, …
- CVE-2017-14035CRITICALCVSS 9.8EG 9.82017-08-30
CrushFTP 8.x before 8.2.0 has a serialization vulnerability.
- CVE-2017-14141HIGHCVSS 7.2EG 7.22017-09-19
The wiki_decode Developer System Helper function in the admin panel in Kaltura before 13.2.0 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object.
- CVE-2017-14702CRITICALCVSS 9.8EG 9.82017-09-30
ERS Data System 1.8.1.0 allows remote attackers to execute arbitrary code, related to "com.branaghgroup.ecers.update.UpdateRequest" object deserialization.
- CVE-2017-15089HIGHCVSS 8.8EG 8.82018-02-15
It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserializatio…
- CVE-2017-15095CRITICALCVSS 9.8EG 9.82018-02-06
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the …
- CVE-2017-15692CRITICALCVSS 9.8EG 9.82018-02-27
In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains access to the Geode locator, they may be able to cause remote code execution if certain classe…
- CVE-2017-15693HIGHCVSS 7.5EG 7.52018-02-27
In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocations cause these objects to be deserialized. A user with DATA:WRITE access to the cluster may be able …
- CVE-2017-15703MEDIUMCVSS 5.0EG 5.02018-01-25
Any authenticated user (valid client certificate but without ACL permissions) could upload a template which contained malicious code and caused a denial of service via Java deserialization attack. The fix to properly handle Java deserializ…
- CVE-2017-1677HIGHCVSS 7.4EG 7.82018-03-22
IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) deserializes the contents of /tmp/connlicj.bin which leads to object injection and potentially arbitrary code execution depending on t…
- CVE-2017-17406CRITICALCVSS 9.8EG 9.82018-01-23
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within an exposed RMI re…
- CVE-2017-17485CRITICALCVSS 9.8EG 9.82018-01-10
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →