Featured

Published on June 4th, 2020 📆 | 2822 Views ⚑

0

Remote Code Execution Deserialization Vulnerability Blocked by Contrast


iSpeech.org

On May 20, 2020, the National Vulnerability Database (NVD) published a new CVE—CVE-2020-9484. The vulnerability associated with CVE-2020-9484 allows any anonymous attacker with internet access to submit a malicious request to a Tomcat Server that has PersistentManager enabled using FileStore. This is not the default setup, but it can be configured by administrators in this way. Red Timmy Security wrote in detail about the vulnerability and exploit.

*** This is a Security Bloggers Network syndicated blog from Security Influencers Blog authored by David Lindner, Director, Application Security. Read the original post at: https://www.contrastsecurity.com/security-influencers/remote-code-execution-deserialization-vulnerability





Source link

Tagged with:



Comments are closed.