← Back
CWE-502

2,964 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

JSON object

Loading...

CVEs (2,964)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Liferay
1Liferay Portal
Jun 17, 2026
Oct 4, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
1Cisco
1Security Manager
Jun 17, 2026
Oct 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecur...Show more
A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a malicious serialized Java object to a specific listener on an affected system. A successful exploit could allow the attacker to execute arbitrary commands on the device with the privileges of casuser.Show less
1Linuxmint
1Mintinstall
Jun 17, 2026
Oct 2, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker, because an unpickle occurs. This is resolved in 8.0.0 and backports.
6Debian
FasterxmlFedoraproject+3 more
26Active Iq Unified Manager
Banking PlatformCommunications Billing And Revenue Management+23 more
Jun 17, 2026
Oct 1, 2019
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the se...Show more
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.Show less
6Debian
FasterxmlFedoraproject+3 more
28Active Iq Unified Manager
Banking PlatformCommunications Billing And Revenue Management+25 more
Jun 17, 2026
Oct 1, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the se...Show more
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling.Show less
1Redhat
1Jboss Enterprise Application Platform
Jun 17, 2026
Oct 1, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2...Show more
A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086 reported for FasterXML jackson-databind by implementing a whitelist approach that will mitigate these vulnerabilities and future ones alike.Show less
1Google
1Android
Jun 17, 2026
Sep 27, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In JobStore, there is a mismatched serialization/deserialization for the "battery-not-low" job attribute. This could lead to a local denial of service with no additional execution privileges needed. User interaction is n...Show more
In JobStore, there is a mismatched serialization/deserialization for the "battery-not-low" job attribute. This could lead to a local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-130173029Show less
1Google
1Android
Jun 17, 2026
Sep 27, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Bluetooth, there is a possible deserialization error due to missing string validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploi...Show more
In Bluetooth, there is a possible deserialization error due to missing string validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-109838537Show less
1Inoideas
1Inoerp
Jun 17, 2026
Sep 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
download.php in inoERP 4.15 allows SQL injection through insecure deserialization.
1Bmc
1Myit Digital Workplace
Jun 17, 2026
Sep 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-authenticated remote commands execution on the Operating System running t...Show more
BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-authenticated remote commands execution on the Operating System running the targeted application. Affected DWP versions: versions: 3.x to 18.x, all versions, service packs, and patches are affected by this vulnerability. Affected SmartIT versions: 1.x, 2.0, 18.05, 18.08, and 19.02, all versions, service packs, and patches are affected by this vulnerability.Show less
1Microfocus
1Service Manager
Jun 17, 2026
Sep 17, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Insecure deserialization of untrusted data in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow...Show more
Insecure deserialization of untrusted data in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow insecure deserialization of untrusted data.Show less
1Apache
1Tapestry
Jun 17, 2026
Sep 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker found the file with the value of the tapestry.hmac-passphrase configuratio...Show more
Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker found the file with the value of the tapestry.hmac-passphrase configuration symbol, most probably the webapp's AppModule class, the value of this symbol could be used to craft a Java deserialization attack, thus running malicious injected Java code. The vector would be the t:formdata parameter from the Form component.Show less
6Debian
FasterxmlFedoraproject+3 more
17Banking Platform
Customer Management And Segmentation FoundationDebian Linux+14 more
Jun 17, 2026
Sep 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.
6Debian
FasterxmlFedoraproject+3 more
19Banking Platform
Customer Management And Segmentation FoundationDebian Linux+16 more
Jun 17, 2026
Sep 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
1Pimcore
1Pimcore
Jun 17, 2026
Sep 14, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in a filename parameter, because PHAR uploads are not blocked and are reachable within the phar://../.....Show more
In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in a filename parameter, because PHAR uploads are not blocked and are reachable within the phar://../../../../../../../../var/www/html/web/var/assets/ directory, a different vulnerability than CVE-2019-10867 and CVE-2019-16318.Show less
1Apache
1Ofbiz
Jun 17, 2026
Sep 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and uses Java deserialization to perform code execution. In the HttpEngine,...Show more
The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and uses Java deserialization to perform code execution. In the HttpEngine, the value of the request parameter "serviceContext" is passed to the "deserialize" method of "XmlSerializer". Apache Ofbiz is affected via two different dependencies: "commons-beanutils" and an out-dated version of "commons-fileupload" Mitigation: Upgrade to 16.11.06 or manually apply the commits from OFBIZ-10770 and OFBIZ-10837 on branch 16Show less
1Gravitatedesign
1Gravitate Qa Tracker
Nov 21, 2024
Sep 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection.
1Sitebuilder Dynamic Components Project
1Sitebuilder Dynamic Components
Nov 21, 2024
Sep 10, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request.
1Alfresco
1Alfresco
Jun 17, 2026
Sep 5, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
An issue was discovered in Alfresco Community Edition 5.2 201707. By leveraging multiple components in the Alfresco Software applications, an exploit chain was observed that allows an attacker to achieve remote code exec...Show more
An issue was discovered in Alfresco Community Edition 5.2 201707. By leveraging multiple components in the Alfresco Software applications, an exploit chain was observed that allows an attacker to achieve remote code execution on the victim machine. The attacker must upload malicious Solr configuration files and then receive a JMX connection from the victim, and serve a Java object that results in deserialization and code execution.Show less
1Epignosishq
1Efront Lms
Jun 17, 2026
Sep 5, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A code execution vulnerability exists in Epignosis eFront LMS v5.2.12. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker can send a crafted web...Show more
A code execution vulnerability exists in Epignosis eFront LMS v5.2.12. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker can send a crafted web parameter to trigger this vulnerability.Show less