CVE-2013-2165

EPSS 24.1%

Remote code execution due to insecure deserialization

發布日:2022/5/13修改日:2023/11/8

描述

A flaw was found in the way JBoss RichFaces handled deserialization. A remote attacker could use this flaw to trigger the execution of the deserialization methods in any serializable class deployed on the server. This could lead to a variety of security impacts depending on the deserialization logic of these classes.

受影響套件(1)

參考連結(7)