CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2013-4521

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1140%
EPSS Percentile40.78th
Published2020年2月6日
Last Modified2024年11月21日

Vulnerability Description

RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data. NOTE: this vulnerability may overlap CVE-2013-2165.

Affected Platforms (CPE)

📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.6.0
📦
Nuxeo

Nuxeo

= 5.8.0

References & Advisories

相關漏洞威脅