← Back
CWE-502

3,196 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

JSON object

Loading...

CVEs (3,196)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Patreon
1Patreon Wordpress
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The patreon-connect plugin before 1.2.2 for WordPress has Object Injection.
6Apache
DebianFedoraproject+3 more
61Agile Plm
Agile Product Lifecycle ManagementAgile Product Lifecycle Management Integration Pack+58 more
Aug 25, 2026
Aug 20, 2019
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, howev...Show more
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.Show less
1Sap
1Commerce Cloud
Jun 17, 2026
Aug 14, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, res...Show more
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.Show less
6Apache
DebianFasterxml+3 more
18Banking Platform
Communications Diameter Signaling RouterCommunications Instant Messaging Server+15 more
Jun 17, 2026
Jul 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint...Show more
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.Show less
1Apache
1Storm
Nov 21, 2024
Jul 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class.
2Oracle
Xstream
10Banking Platform
Business Activity MonitoringCommunications Billing And Revenue Management Elastic Charging Engine+7 more
Jun 17, 2026
Jul 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary...Show more
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)Show less
1Teller
1Slanger
Jun 17, 2026
Jul 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Slanger 0.6.0 is affected by: Remote Code Execution (RCE). The impact is: A remote attacker can execute arbitrary commands by sending a crafted request to the server. The component is: Message handler & request validator...Show more
Slanger 0.6.0 is affected by: Remote Code Execution (RCE). The impact is: A remote attacker can execute arbitrary commands by sending a crafted request to the server. The component is: Message handler & request validator. The attack vector is: Remote unauthenticated. The fixed version is: after commit 5267b455caeb2e055cccf0d2b6a22727c111f5c3.Show less
1Osbs Client Project
1Osbs Client
Jun 17, 2026
Jul 11, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A flaw was found in the yaml.load() function in the osbs-client versions since 0.46 before 0.56.1. Insecure use of the yaml.load() function allowed the user to load any suspicious object for code execution via the parsin...Show more
A flaw was found in the yaml.load() function in the osbs-client versions since 0.46 before 0.56.1. Insecure use of the yaml.load() function allowed the user to load any suspicious object for code execution via the parsing of malicious YAML files.Show less
3Fasterxml
OracleRedhat
7Clusterware
Communications Instant Messaging ServerGlobal Lifecycle Management Opatch+4 more
Nov 21, 2024
Jul 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.
1Typo3
1Typo3
Jun 17, 2026
Jul 9, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrusted Data.
3Debian
FasterxmlRedhat
3Debian Linux
Enterprise LinuxJackson Databind
Jun 17, 2026
Jun 24, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content,...Show more
FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content, remote code execution may be possible.Show less
1Akamai
1Cloudtest
Jun 17, 2026
Jun 21, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Akamai CloudTest before 58.30 allows remote code execution.
1Ethereum
1Ethereumj
Nov 21, 2024
Jun 20, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and decoder.readObject in crypto/ECKey.java. When a node syncs and mines a new block, arbitrary OS command...Show more
An issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and decoder.readObject in crypto/ECKey.java. When a node syncs and mines a new block, arbitrary OS commands can be run on the server.Show less
2Debian
Fasterxml
2Debian Linux
Jackson Databind
Jun 17, 2026
Jun 19, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the servi...Show more
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.Show less
2Misp
Misp Project
2Misp
Misp
Jun 22, 2026
Jun 18, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
app/Model/Server.php in MISP 2.4.109 allows remote command execution by a super administrator because the PHP file_exists function is used with user-controlled entries, and phar:// URLs trigger deserialization.
1Shopware
1Shopware
Jun 17, 2026
Jun 13, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiat...Show more
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. An attacker can leverage this deserialization to achieve remote code execution. NOTE: this issue is a bypass for a CVE-2017-18357 whitelist patch.Show less
1Adobe
1Coldfusion
Jun 17, 2026
Jun 12, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
1Parso Project
1Parso
Jun 17, 2026
Jun 6, 2019
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
A deserialization vulnerability exists in the way parso through 0.4.0 handles grammar parsing from the cache. Cache loading relies on pickle and, provided that an evil pickle can be written to a cache grammar file and th...Show more
A deserialization vulnerability exists in the way parso through 0.4.0 handles grammar parsing from the cache. Cache loading relies on pickle and, provided that an evil pickle can be written to a cache grammar file and that its parsing can be triggered, this flaw leads to Arbitrary Code Execution. NOTE: This is disputed because "the cache directory is not under control of the attacker in any common configuration.Show less
1Sitecore
1Experience Platform
Jun 17, 2026
Jun 6, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user with necessary permissions is able to remotely execute OS commands by s...Show more
Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user with necessary permissions is able to remotely execute OS commands by sending a crafted serialized object.Show less
1Hp
1Intelligent Management Center
Jun 17, 2026
Jun 5, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.