CVE-2021-22855

CRITICAL

HR Portal - Remote Code Execution via Untrusted Deserialization

Title source: llm
STIX 2.1

Description

The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can send malicious serialized objects to execute arbitrary commands.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-4405-2ddde-1.html

Scores

CVSS v3 9.8
EPSS 0.0197
EPSS Percentile 77.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-502
Status published
Products (1)
hr_portal_project/hr_portal 7.3.2020.1013
Published Feb 17, 2021
Tracked Since Feb 18, 2026