Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
9.8
CVE-2024-46983
- EPSS 0.16%
- Published 19.09.2024 23:15:11
- Last modified 25.09.2024 17:46:48
sofa-hessian is an internal improved version of Hessian3/4 powered by Ant Group CO., Ltd. The SOFA Hessian protocol uses a blacklist mechanism to restrict deserialization of potentially dangerous classes for security protection. But there is a gadget...
9.8
CVE-2019-9212
- EPSS 0.88%
- Published 27.02.2019 17:29:00
- Last modified 21.11.2024 04:51:13
SOFA-Hessian through 4.0.2 allows remote attackers to execute arbitrary commands via a crafted serialized Hessian object because blacklisting of com.caucho.naming.QName and com.sun.org.apache.xpath.internal.objects.XString is mishandled, related to R...
1