CVE-2017-9830
27.06.2017, 18:29
Remote Code Execution is possible in Code42 CrashPlan 5.4.x via the org.apache.commons.ssl.rmi.DateRMI Java class, because (upon instantiation) it creates an RMI server that listens on a TCP port and deserializes objects sent by TCP clients.Enginsight
Vendor | Product | Version |
---|---|---|
code42 | crashplan | 5.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration