Apache Struts2 Jackson Library Remote Code Execution (CVE-2017-15095; CVE-2017-7525)

Vulnerability exists in Jackson data-bind library. This vulnerability is due to deserialization of untrusted data. A successful exploitation of this issue could allow an attacker to execute arbitrary code on the remote system.

from Check Point Update Services Advisories http://ift.tt/2BB8RiU

No comments:

Post a Comment

Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading

Cybersecurity researchers have uncovered a new phishing campaign that exploits social media private messages to propagate malicious payloads...