* Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated input. If this service is supplied with raw serialised Java objects, it deserialises them back into Java objects in memory, giving rise to a remote code execution vulnerability. NOTE: the vendor disputes that this is a vulnerability, stating it is "already mitigated by the internal firewall that limits access to configuration services to localhost.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-10-24T21:00:00

Updated: 2024-08-05T11:01:14.967Z

Reserved: 2018-10-05T00:00:00

Link: CVE-2018-18013

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-10-24T21:29:00.657

Modified: 2024-08-05T11:15:38.463

Link: CVE-2018-18013

cve-icon Redhat

No data.