Vulnerability Name: | CVE-2019-17570 (CCN-174690) | ||||||||||||||||
Assigned: | 2019-10-14 | ||||||||||||||||
Published: | 2020-01-16 | ||||||||||||||||
Updated: | 2022-09-03 | ||||||||||||||||
Summary: | An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue will not be fixed. | ||||||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.6 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
8.6 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
| ||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||
Vulnerability Type: | CWE-502 | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-17570 Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20200124 RE: [CVE-2019-17570] xmlrpc-common untrusted deserialization Source: REDHAT Type: Third Party Advisory RHSA-2020:0310 Source: CONFIRM Type: Issue Tracking, Patch, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-17570; Source: XF Type: UNKNOWN apachexmlrpc-cve201917570-code-exec(174690) Source: MISC Type: Exploit, Third Party Advisory https://github.com/orangecertcc/security-research/security/advisories/GHSA-x2r6-4m45-m4jp Source: CONFIRM Type: Mailing List, Vendor Advisory https://lists.apache.org/thread.html/846551673bbb7ec8d691008215384bcef03a3fb004d2da845cfe88ee%401390230951%40%3Cdev.ws.apache.org%3E Source: MLIST Type: Mailing List, Third Party Advisory [debian-lts-announce] 20200130 [SECURITY] [DLA 2078-1] libxmlrpc3-java security update Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2020-1d0635bd71 Source: BUGTRAQ Type: Mailing List, Third Party Advisory 20200210 [SECURITY] [DSA 4619-1] libxmlrpc3-java security update Source: CCN Type: oss-sec Mailing List, Thu, 16 Jan 2020 08:59:51 +0000 [CVE-2019-17570] xmlrpc-common untrusted deserialization Source: UBUNTU Type: Patch, Third Party Advisory USN-4496-1 Source: CCN Type: Apache XML-RPC Web site Apache XML-RPC Source: DEBIAN Type: Third Party Advisory DSA-4619 Source: CCN Type: WhiteSource Vulnerability Database CVE-2019-17570 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration 4: Configuration 5: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |