9

CVE-2021-36981

Exploit
In the server in SerNet verinice before 1.22.2, insecure Java deserialization allows remote authenticated attackers to execute arbitrary code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SernetVerinice Version < 1.22.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.05% 0.924
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

https://github.com/0xBrAinsTorM/CVE-2021-36981
Exploit
Issue Tracking
https://github.com/SerNet/verinice/compare/1.22.1...1.22.2
Patch
https://verinice.com/en/support/security-advisory
Patch
Vendor Advisory
https://www.secianus.de/worum-geht-es/aktuelle-meldung/cve-2021-36981-verinicepro-unsafe-java-deserialization
Third Party Advisory
Exploit