Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product allows a remote attacker to inject unsecure serialized Java object using a specially crafted HTTP request, resulting in an unauthenticated remote code execution on the server.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-01-28T19:37:46
Updated: 2024-08-03T16:45:51.393Z
Reserved: 2021-01-15T00:00:00
Link: CVE-2021-3160
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-01-28T20:15:13.227
Modified: 2024-11-21T06:21:01.847
Link: CVE-2021-3160
Redhat
No data.