CVE-2013-4521
06.02.2020, 16:15
RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data. NOTE: this vulnerability may overlap CVE-2013-2165.Enginsight
Vendor | Product | Version |
---|---|---|
nuxeo | nuxeo | 5.6.0 |
nuxeo | nuxeo | 5.6.0:hotfix01 |
nuxeo | nuxeo | 5.6.0:hotfix02 |
nuxeo | nuxeo | 5.6.0:hotfix03 |
nuxeo | nuxeo | 5.6.0:hotfix04 |
nuxeo | nuxeo | 5.6.0:hotfix05 |
nuxeo | nuxeo | 5.6.0:hotfix06 |
nuxeo | nuxeo | 5.6.0:hotfix07 |
nuxeo | nuxeo | 5.6.0:hotfix08 |
nuxeo | nuxeo | 5.6.0:hotfix09 |
nuxeo | nuxeo | 5.6.0:hotfix10 |
nuxeo | nuxeo | 5.6.0:hotfix11 |
nuxeo | nuxeo | 5.6.0:hotfix12 |
nuxeo | nuxeo | 5.6.0:hotfix13 |
nuxeo | nuxeo | 5.6.0:hotfix14 |
nuxeo | nuxeo | 5.6.0:hotfix15 |
nuxeo | nuxeo | 5.6.0:hotfix16 |
nuxeo | nuxeo | 5.6.0:hotfix17 |
nuxeo | nuxeo | 5.6.0:hotfix18 |
nuxeo | nuxeo | 5.6.0:hotfix19 |
nuxeo | nuxeo | 5.6.0:hotfix20 |
nuxeo | nuxeo | 5.6.0:hotfix21 |
nuxeo | nuxeo | 5.6.0:hotfix22 |
nuxeo | nuxeo | 5.6.0:hotfix23 |
nuxeo | nuxeo | 5.6.0:hotfix24 |
nuxeo | nuxeo | 5.6.0:hotfix25 |
nuxeo | nuxeo | 5.6.0:hotfix26 |
nuxeo | nuxeo | 5.8.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References