9.8

CVE-2017-5983

The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AtlassianJira Version4.2.4
AtlassianJira Version4.3
AtlassianJira Version4.3.1
AtlassianJira Version4.3.2
AtlassianJira Version4.3.3
AtlassianJira Version4.3.4
AtlassianJira Version4.4
AtlassianJira Version4.4.1
AtlassianJira Version4.4.2
AtlassianJira Version4.4.3
AtlassianJira Version4.4.4
AtlassianJira Version4.4.5
AtlassianJira Version5.0
AtlassianJira Version5.0.1
AtlassianJira Version5.0.2
AtlassianJira Version5.0.3
AtlassianJira Version5.0.4
AtlassianJira Version5.0.5
AtlassianJira Version5.0.7
AtlassianJira Version5.1
AtlassianJira Version5.1.1
AtlassianJira Version5.1.2
AtlassianJira Version5.1.3
AtlassianJira Version5.1.4
AtlassianJira Version5.1.5
AtlassianJira Version5.1.6
AtlassianJira Version5.1.7
AtlassianJira Version5.1.8
AtlassianJira Version5.2
AtlassianJira Version5.2.1
AtlassianJira Version5.2.2
AtlassianJira Version5.2.3
AtlassianJira Version5.2.4
AtlassianJira Version5.2.5
AtlassianJira Version5.2.6
AtlassianJira Version5.2.7
AtlassianJira Version5.2.8
AtlassianJira Version5.2.9
AtlassianJira Version5.2.10
AtlassianJira Version5.2.11
AtlassianJira Version6.0
AtlassianJira Version6.0.1
AtlassianJira Version6.0.2
AtlassianJira Version6.0.3
AtlassianJira Version6.0.4
AtlassianJira Version6.0.5
AtlassianJira Version6.0.7
AtlassianJira Version6.0.8
AtlassianJira Version6.1
AtlassianJira Version6.1.1
AtlassianJira Version6.1.2
AtlassianJira Version6.1.3
AtlassianJira Version6.1.4
AtlassianJira Version6.1.5
AtlassianJira Version6.1.6
AtlassianJira Version6.1.7
AtlassianJira Version6.1.8
AtlassianJira Version6.1.9
AtlassianJira Version6.2
AtlassianJira Version6.2.1
AtlassianJira Version6.2.2
AtlassianJira Version6.2.3
AtlassianJira Version6.2.4
AtlassianJira Version6.2.5
AtlassianJira Version6.2.6
AtlassianJira Version6.2.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 16.24% 0.965
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

http://codewhitesec.blogspot.com/2017/04/amf.html
Technical Description
http://www.securityfocus.com/bid/97379
Third Party Advisory
VDB Entry
https://confluence.atlassian.com/jira063/jira-security-advisory-2017-03-09-875604401.html
Vendor Advisory
https://jira.atlassian.com/browse/JRASERVER-64077
Vendor Advisory
https://www.kb.cert.org/vuls/id/307983
Third Party Advisory
US Government Resource
VDB Entry