Description
TylerTech Eagle 2018.3.11 deserializes untrusted user input, resulting in remote code execution via a crafted Java object to the recorder/ServiceManager?service=tyler.empire.settings.SettingManager URI.
Exploits (1)
Scores
CVSS v3
8.8
EPSS
0.0199
EPSS Percentile
83.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-502
Status
published
Products (1)
tylertech/eagle
2018.3.11
Published
May 13, 2020
Tracked Since
Feb 18, 2026