Impact
Unsafe deserialization of Java objects within DHIS2 enables arbitrary code execution. The flaw is classified as CWE-502 and carries a CVSS score of 9.1, indicating that if exploited an attacker can gain full control over the affected system.
Affected Systems
DHIS2 releases from 2.42.0 up to, but not including, 2.42.5.1 and from 2.43.0 up to, but not including, 2.43.0.1 contain the vulnerability. The issue was corrected in releases 2.42.5.1, 2.43.0.1, and later 2.44, so any deployment on a vulnerable version must be upgraded.
Risk and Exploitability
The vulnerability can be triggered remotely from any network location that can reach the Java deserialization endpoint. No authentication is required, so an unauthenticated attacker can send a crafted payload and immediately obtain full code execution, compromising confidentiality, integrity, and availability. With no EPSS metric available and the issue not listed in the CISA KEV catalog, exposure depends mainly on the application’s network reachability and any existing network mitigations.
OpenCVE Enrichment