CVE-2019-17570
23.01.2020, 22:15
An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue will not be fixed.Enginsight
Vendor | Product | Version |
---|---|---|
apache | xml-rpc | 3.1 |
apache | xml-rpc | 3.1.1 |
apache | xml-rpc | 3.1.2 |
apache | xml-rpc | 3.1.3 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
canonical | ubuntu_linux | 16.04 |
canonical | ubuntu_linux | 18.04 |
redhat | software_collections | 1.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References