← Back
CWE-502

3,196 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

JSON object

Loading...

CVEs (3,196)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Debian
FasterxmlNetapp+1 more
26Agile Plm
Agile Product Lifecycle ManagementAutovue For Agile Product Lifecycle Management+23 more
Aug 25, 2026
Mar 31, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms)...Show more
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).Show less
1Mongodb
1Bson
Jun 17, 2026
Mar 30, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialized as a document rathe...Show more
All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialized as a document rather than the intended BSON type.Show less
4Debian
FasterxmlNetapp+1 more
32Agile Plm
Agile Product Lifecycle ManagementAutovue For Agile Product Lifecycle Management+29 more
Aug 25, 2026
Mar 26, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
4Debian
FasterxmlNetapp+1 more
32Agile Plm
Agile Product Lifecycle ManagementAutovue For Agile Product Lifecycle Management+29 more
Aug 25, 2026
Mar 26, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
1Rockwellautomation
1Factorytalk Services Platform
Jun 17, 2026
Mar 23, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In Rockwell Automation all versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platform, FactoryTalk Diagnostics exposes a .NET Remoting endpoint via RNADiagnosticsSrv.exe at TCPtcp/8082...Show more
In Rockwell Automation all versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platform, FactoryTalk Diagnostics exposes a .NET Remoting endpoint via RNADiagnosticsSrv.exe at TCPtcp/8082, which can insecurely deserialize untrusted data.Show less
1Liferay
1Liferay Portal
Jun 17, 2026
Mar 20, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
4Debian
FasterxmlNetapp+1 more
32Agile Plm
Agile Product Lifecycle ManagementAutovue For Agile Product Lifecycle Management+29 more
Aug 25, 2026
Mar 18, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
4Debian
FasterxmlNetapp+1 more
32Agile Plm
Agile Product Lifecycle ManagementAutovue For Agile Product Lifecycle Management+29 more
Aug 25, 2026
Mar 18, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jm...Show more
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).Show less
1Pydio
1Pydio
Jun 17, 2026
Mar 17, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/uploader.http/HttpDownload.php. An authenticated user with basic privileges can inje...Show more
A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/uploader.http/HttpDownload.php. An authenticated user with basic privileges can inject objects and achieve remote code execution.Show less
1Pydio
1Pydio
Jun 17, 2026
Mar 17, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/core.access/src/RecycleBinManager.php. An authenticated user with basic privileges c...Show more
A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/core.access/src/RecycleBinManager.php. An authenticated user with basic privileges can inject objects and achieve remote code execution.Show less
1Apache
1Shardingsphere
Jun 17, 2026
Mar 11, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load datasource configuration. SnakeYAML allows to unmarshal data to a Java...Show more
In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load datasource configuration. SnakeYAML allows to unmarshal data to a Java type By using the YAML tag. Unmarshalling untrusted data can lead to security flaws of RCE.Show less
1Hp
1Storage Essentials
Nov 21, 2024
Mar 10, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In HPE Storage Essentials 9.5.0.142, there is Unauthenticated Java Deserialization with remote code execution via OS commands in a request to invoker/JMXInvokerServlet, aka PSRT110461.
1Lexmark
1Markvision Enterprise
Nov 21, 2024
Mar 9, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Lexmark Markvision Enterprise before 2.3.0 misuses the Apache Commons Collections Library, leading to remote code execution because of Java deserialization.
1Jenkins
1Literate
Jun 17, 2026
Mar 9, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Jenkins Literate Plugin 1.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
1Dell
1Security Management Server
Jun 17, 2026
Mar 6, 2020
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
Dell Security Management Server versions prior to 10.2.10 contain a Java RMI Deserialization of Untrusted Data vulnerability. When the server is exposed to the internet and Windows Firewall is disabled, a remote unauthen...Show more
Dell Security Management Server versions prior to 10.2.10 contain a Java RMI Deserialization of Untrusted Data vulnerability. When the server is exposed to the internet and Windows Firewall is disabled, a remote unauthenticated attacker may exploit this vulnerability by sending a crafted RMI request to execute arbitrary code on the target host.Show less
1Zohocorp
1Manageengine Desktop Central
Jun 17, 2026
Mar 6, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUpload...Show more
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.Show less
3Fasterxml
NetappOracle
4Goldengate Stream Analytics
Jackson DatabindOncommand Api Services+1 more
Jun 17, 2026
Mar 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction wi...Show more
A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultTyping()` or when @JsonTypeInfo is using `Id.CLASS` or `Id.MINIMAL_CLASS` or in any other way which ObjectMapper.readValue might instantiate objects from unsafe sources. An attacker could use this flaw to execute arbitrary code.Show less
3Apache
FasterxmlRedhat
8Decision Manager
GeodeJackson Databind+5 more
Jun 17, 2026
Mar 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An atta...Show more
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.Show less
4Debian
FasterxmlNetapp+1 more
26Active Iq Unified Manager
Agile PlmAgile Product Lifecycle Management+23 more
Aug 25, 2026
Mar 2, 2020
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).
4Debian
FasterxmlNetapp+1 more
16Active Iq Unified Manager
Autovue For Agile Product Lifecycle ManagementBanking Platform+13 more
Jun 17, 2026
Mar 2, 2020
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).