CVE-2017-9424

CRITICAL

IdeaBlade Breeze <1.6.5 - Code Injection

Title source: llm

Description

IdeaBlade Breeze Breeze.Server.NET before 1.6.5 allows remote attackers to execute arbitrary code, related to use of TypeNameHandling in JSON deserialization.

Scores

CVSS v3 9.8
EPSS 0.0443
EPSS Percentile 88.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status draft

Affected Products (1)

ideablade/breeze.server.net < 1.6.0

Timeline

Published Jun 22, 2017
Tracked Since Feb 18, 2026