CVE-2021-3160
28.01.2021, 20:15
Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product allows a remote attacker to inject unsecure serialized Java object using a specially crafted HTTP request, resulting in an unauthenticated remote code execution on the server.Enginsight
Vendor | Product | Version |
---|---|---|
aca | assuweb | 359.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References