CVE-2017-9424
CRITICALIdeaBlade Breeze <1.6.5 - Code Injection
Title source: llmDescription
IdeaBlade Breeze Breeze.Server.NET before 1.6.5 allows remote attackers to execute arbitrary code, related to use of TypeNameHandling in JSON deserialization.
Scores
CVSS v3
9.8
EPSS
0.0443
EPSS Percentile
88.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
draft
Affected Products (1)
ideablade/breeze.server.net
< 1.6.0
Timeline
Published
Jun 22, 2017
Tracked Since
Feb 18, 2026