Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Pivotal/Spring Spring-flex's Action Message Format (AMF3) Java implementation is vulnerable to insecure deserialization
Vulnerability Description
The Java implementations of AMF3 deserializers in Pivotal/Spring Spring-flex derive class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExternalizable. A remote attacker with the ability to spoof or control an RMI server connection may be able to send serialized Java objects that execute arbitrary code when deserialized.
CVSS Information
N/A
Vulnerability Type
可信数据的反序列化
Vulnerability Title
Pivotal Spring Flex 安全漏洞
Vulnerability Description
Pivotal Spring Flex是美国Pivotal Software公司的一款集成BlazeDS用于远程处理和消息传递的客户端。 Pivotal Spring Flex中存在远程代码执行漏洞。远程攻击者可利用该漏洞在受影响应用程序上下文中执行任意代码,造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A