CVE-2022-22963
- EPSS 94.46%
- Veröffentlicht 01.04.2022 23:15:13
- Zuletzt bearbeitet 30.10.2025 19:56:53
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access ...
CVE-2022-22965
- EPSS 94.44%
- Veröffentlicht 01.04.2022 23:15:13
- Zuletzt bearbeitet 30.10.2025 19:56:43
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Sp...
CVE-2021-43859
- EPSS 2.03%
- Veröffentlicht 01.02.2022 12:15:08
- Zuletzt bearbeitet 03.11.2025 22:15:52
XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resul...
CVE-2021-44832
- EPSS 52.77%
- Veröffentlicht 28.12.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:31:34
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has ...
CVE-2021-39152
- EPSS 67.83%
- Veröffentlicht 23.08.2021 19:15:13
- Zuletzt bearbeitet 23.05.2025 16:47:47
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed inp...
CVE-2021-39150
- EPSS 1.97%
- Veröffentlicht 23.08.2021 19:15:12
- Zuletzt bearbeitet 23.05.2025 16:48:02
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed inp...
CVE-2021-39140
- EPSS 0.04%
- Veröffentlicht 23.08.2021 19:15:10
- Zuletzt bearbeitet 23.05.2025 16:50:34
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload r...
CVE-2021-39154
- EPSS 0.71%
- Veröffentlicht 23.08.2021 18:15:13
- Zuletzt bearbeitet 23.05.2025 16:47:35
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user...
CVE-2021-39141
- EPSS 84.54%
- Veröffentlicht 23.08.2021 18:15:12
- Zuletzt bearbeitet 23.05.2025 16:52:36
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user...
CVE-2021-39144
- EPSS 94.38%
- Veröffentlicht 23.08.2021 18:15:12
- Zuletzt bearbeitet 24.10.2025 14:47:35
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user...