← back
CVE-2019-17564observed exploitation

CVE-2019-17564

52Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 37%
from disclosure to weapon
Published on NVDApr 1
VulnCheck+1500d
exploitation probability
37%top 2% of all CVEs
observed exploitation
yesVulnCheck
Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables HTTP. This issue affected Apache Dubbo 2.7.0 to 2.7.4, 2.6.0 to 2.6.7, and all 2.5.x versions.
Affected products
Apache · Apache Dubbo