|
CVE-2020-11113
|
High
|
2020-03-31
|
No exploit published
|
No public exploit
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
|
|
CVE-2020-4276
|
High
|
2020-03-26
|
No fix identified
|
Proof of concept only
|
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. X-Force ID: 175984.
|
|
CVE-2020-7961
|
Critical
|
2020-03-20
|
Protected by RASP
|
Exploited in the wild
|
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
|
|
CVE-2020-10673
|
High
|
2020-03-18
|
No exploit published
|
Proof of concept only
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
|
|
CVE-2020-1947
|
Critical
|
2020-03-11
|
No exploit published
|
Proof of concept only
|
In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load datasource configuration. SnakeYAML allows to unmarshal data to a Java type By using the YAML tag. Unmarshalling untrusted data can lead to security flaws of RCE.
|
|
CVE-2020-2140
|
Medium
|
2020-03-09
|
Mitigation candidate
|
Working exploit published
|
Jenkins Audit Trail Plugin 3.2 and earlier does not escape the error message for the URL Patterns field form validation, resulting in a reflected cross-site scripting vulnerability.
|
|
CVE-2020-5405
|
Medium
|
2020-03-05
|
Protected by RASP
|
Working exploit published
|
Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.
|
|
CVE-2020-9548
|
Critical
|
2020-03-02
|
Mitigation candidate
|
Working exploit published
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).
|
|
CVE-2020-9547
|
Critical
|
2020-03-02
|
Mitigation candidate
|
Working exploit published
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).
|