CVE-2020-23620
CRITICALOrlansoft ERP - Remote Code Execution via Insecure Java Deserialization
Title source: llmDescription
The Java Remote Management Interface of all versions of Orlansoft ERP was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_misc
https://orlansoft.com/
Third Party Advisory x_refsource_misc
https://gist.github.com/fuzzKitty/95106430aa09760ebdcfa6304777f31f
Scores
CVSS v3
9.8
EPSS
0.0194
EPSS Percentile
77.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-502
Status
published
Products (1)
orlansoft/orlansoft_erp
Published
May 02, 2022
Tracked Since
Feb 18, 2026