Description
The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can send malicious serialized objects to execute arbitrary commands.
No analysis available yet.
Remediation
Vendor Solution
Update to version 7.3.2020.1110
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-9990 | The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can send malicious serialized objects to execute arbitrary commands. |
References
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T20:52:52.968Z
Reserved: 2021-01-06T00:00:00.000Z
Link: CVE-2021-22855
No data.
Status : Modified
Published: 2021-02-17T14:15:19.327
Modified: 2024-11-21T05:50:46.340
Link: CVE-2021-22855
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD