HPE Intelligent Management Center WebDMServlet Insecure Deserialization (CVE-2017-12558)

An insecure deserialization vulnerability exists in HPE Intelligent Management Center. The vulnerability is due to deserialization of untrusted data by the WebDMServlet while having vulnerable classes in the code path. A remote, unauthenticated attacker can exploit this vulnerability by sending a maliciously crafted serialized object.

from Check Point Update Services Advisories http://ift.tt/2DcBK6R

No comments:

Post a Comment

Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading

Cybersecurity researchers have uncovered a new phishing campaign that exploits social media private messages to propagate malicious payloads...