Showing 1 vulnerability on this page for Apache XML-RPC

Signals CISA KEV Ransomware Nuclei
apache vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Insecure Deserialization in Apache XML-RPC

An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue will not be fixed.

CWE-502Jan 23, 2020
CVSS9.8v3.1EPSS49.3%PoCs2SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX