Impact
A flaw in Cosminexus Component Container allows it to deserialize external data without verifying its origin, which can lead to arbitrary code execution. The vulnerability is classified as CWE-502 and has a CVSS score of 9.8, indicating that an attacker can raise full system privileges on the affected host. The description does not mention specific exploitation details, but such deserialization bugs typically permit malicious payloads that, when processed by the container, cause the execution of attacker‑supplied code.
Affected Systems
The impacted product is Hitachi Cosminexus Component Container. Versions from 09-00 through 09-00-18, 09-50 through 09-50-22, 09-70 before 09-70-28, 09-80 before 09-80-05, 09-87 before 09-87-10, 11-00 before 11-00-13, 11-10 through 11-10-11, 11-20 before 11-20-10, 11-30 through 11-30-08, 11-40 through 11-40-03, 11-50 through 11-50-03, 11-60 before 11-60-03, and 11-70-01 before 11-70-03 are all vulnerable.
Risk and Exploitability
The high CVSS score indicates severe potential impact if exploited. Although the EPSS score is not available, the lack of KEV listing does not diminish its inherent risk because the vulnerability still permits remote or local delivery of malicious serialized data. An attacker who can send such data, for example through a network interface or a configuration file, could execute code with the container's privileges. Given the severity and lack of mitigation information in the advisory, the vulnerability remains a top priority for remediation.
OpenCVE Enrichment