The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can send malicious serialized objects to execute arbitrary commands.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-9990 | The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can send malicious serialized objects to execute arbitrary commands. |
Fixes
Solution
Update to version 7.3.2020.1110
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T20:52:52.968Z
Reserved: 2021-01-06T00:00:00
Link: CVE-2021-22855
No data.
Status : Modified
Published: 2021-02-17T14:15:19.327
Modified: 2024-11-21T05:50:46.340
Link: CVE-2021-22855
No data.
OpenCVE Enrichment
No data.
EUVD