CVE-2022-25647
HIGHGoogle Gson < 2.8.9 - Insecure Deserialization
Title source: ruleDescription
The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.
References (8)
Scores
CVSS v3
7.7
EPSS
0.0208
EPSS Percentile
83.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (15)
google/gson
< 2.8.9
debian/debian_linux
debian/debian_linux
debian/debian_linux
netapp/active_iq_unified_manager
netapp/active_iq_unified_manager
netapp/active_iq_unified_manager
oracle/financial_services_crime_and_compliance_management_studio
oracle/financial_services_crime_and_compliance_management_studio
oracle/graalvm
oracle/graalvm
oracle/graalvm
oracle/retail_order_broker
oracle/retail_order_broker
com.google.code.gson/gson
< 2.8.9Maven
Timeline
Published
May 01, 2022
Tracked Since
Feb 18, 2026