← Back

CVE-2019-18956

nvd nist
Published: Dec 17, 2019Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Divisa Proxia Suite 9 < 9.12.16, 9.11.19, 9.10.26, 9.9.8, 9.8.43 and 9.7.10, 10.0 < 10.0.32, and 10.1 < 10.1.5, SparkSpace 1.0 < 1.0.30, 1.1 < 1.1.2, and 1.2 < 1.2.4, and Proxia PHR 1.0 < 1.0.30 and 1.1 < 1.1.2 allows remote code execution via untrusted Java deserialization. The proxia-error cookie is insecurely deserialized in every request (GET or POST). Thus, an unauthenticated attacker can easily craft a seria1.0lized payload in order to execute arbitrary code via the prepareError function in the com.divisait.dv2ee.controller.MVCControllerServlet class of the dv2eemvc.jar component. allows remote code execution via untrusted Java deserialization. The proxia-error cookie is insecurely deserialized in every request (GET or POST). Thus, an unauthenticated attacker can easily craft a serialized payload in order to execute arbitrary code via the prepareError function in the com.divisait.dv2ee.controller.MVCControllerServlet class of the dv2eemvc.jar component. Affected products include Proxia Premium Edition 2017 and Sparkspace.

Affected (16)

4 products
Dv2eemvc
Proxia Phr
Proxia Suite
Sparkspace
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
Divisait
From 17-62 to 17-147
From 18.6 to 18.6.42
From 19.0 to 19.0.13
From 19.1 to 19.1.19
From 19.2 to 19.2.41
From 19.3 to 19.3.37
From 19.4 to 19.4.13
From 20.0 to 20.0.13
Divisait
From 1.0 to 1.0.30
From 1.1 to 1.1.2
Divisait
From 10.0 to 10.0.32
From 10.1 to 10.1.5
From 9.0 to 9.12.16
Divisait
From 1.0 to 1.0.30
From 1.1 to 1.1.2
From 1.2 to 1.2.4

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.