The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can send malicious serialized objects to execute arbitrary commands.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2021-02-17T13:30:20.743977Z
Updated: 2024-09-16T20:52:52.968Z
Reserved: 2021-01-06T00:00:00
Link: CVE-2021-22855
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-02-17T14:15:19.327
Modified: 2024-11-21T05:50:46.340
Link: CVE-2021-22855
Redhat
No data.