9.8

CVE-2017-5983

The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AtlassianJira Version4.2.4
AtlassianJira Version4.3
AtlassianJira Version4.3.1
AtlassianJira Version4.3.2
AtlassianJira Version4.3.3
AtlassianJira Version4.3.4
AtlassianJira Version4.4
AtlassianJira Version4.4.1
AtlassianJira Version4.4.2
AtlassianJira Version4.4.3
AtlassianJira Version4.4.4
AtlassianJira Version4.4.5
AtlassianJira Version5.0
AtlassianJira Version5.0.1
AtlassianJira Version5.0.2
AtlassianJira Version5.0.3
AtlassianJira Version5.0.4
AtlassianJira Version5.0.5
AtlassianJira Version5.0.7
AtlassianJira Version5.1
AtlassianJira Version5.1.1
AtlassianJira Version5.1.2
AtlassianJira Version5.1.3
AtlassianJira Version5.1.4
AtlassianJira Version5.1.5
AtlassianJira Version5.1.6
AtlassianJira Version5.1.7
AtlassianJira Version5.1.8
AtlassianJira Version5.2
AtlassianJira Version5.2.1
AtlassianJira Version5.2.2
AtlassianJira Version5.2.3
AtlassianJira Version5.2.4
AtlassianJira Version5.2.5
AtlassianJira Version5.2.6
AtlassianJira Version5.2.7
AtlassianJira Version5.2.8
AtlassianJira Version5.2.9
AtlassianJira Version5.2.10
AtlassianJira Version5.2.11
AtlassianJira Version6.0
AtlassianJira Version6.0.1
AtlassianJira Version6.0.2
AtlassianJira Version6.0.3
AtlassianJira Version6.0.4
AtlassianJira Version6.0.5
AtlassianJira Version6.0.7
AtlassianJira Version6.0.8
AtlassianJira Version6.1
AtlassianJira Version6.1.1
AtlassianJira Version6.1.2
AtlassianJira Version6.1.3
AtlassianJira Version6.1.4
AtlassianJira Version6.1.5
AtlassianJira Version6.1.6
AtlassianJira Version6.1.7
AtlassianJira Version6.1.8
AtlassianJira Version6.1.9
AtlassianJira Version6.2
AtlassianJira Version6.2.1
AtlassianJira Version6.2.2
AtlassianJira Version6.2.3
AtlassianJira Version6.2.4
AtlassianJira Version6.2.5
AtlassianJira Version6.2.6
AtlassianJira Version6.2.7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.39% 0.919
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.