CVE-2021-22855
CRITICALHR Portal - Remote Code Execution via Untrusted Deserialization
Title source: llmDescription
The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can send malicious serialized objects to execute arbitrary commands.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-4405-2ddde-1.html
Third Party Advisory x_refsource_confirm
https://www.chtsecurity.com/news/d334641f-2b28-4eab-a5ed-c6ec6740557e
Scores
CVSS v3
9.8
EPSS
0.0197
EPSS Percentile
77.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-502
Status
published
Products (1)
hr_portal_project/hr_portal
7.3.2020.1013
Published
Feb 17, 2021
Tracked Since
Feb 18, 2026