CVE-2019-16112
HIGHTylerTech Eagle 2018.3.11 - Remote Code Execution via Untrusted Java Deserialization
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-16112. PoCs published by Anthony Cole.
AI-analyzed exploit summary This exploit leverages a Java deserialization vulnerability in TylerTech Eagle 2018.3.11 to achieve remote code execution. It uses ysoserial to generate a malicious payload, compresses it, and sends it to the vulnerable endpoint.
Description
TylerTech Eagle 2018.3.11 deserializes untrusted user input, resulting in remote code execution via a crafted Java object to the recorder/ServiceManager?service=tyler.empire.settings.SettingManager URI.
Exploits (1)
This exploit leverages a Java deserialization vulnerability in TylerTech Eagle 2018.3.11 to achieve remote code execution. It uses ysoserial to generate a malicious payload, compresses it, and sends it to the vulnerable endpoint.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H