Fallos del tipo CWE-502

2661 resultados

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados recebidos (JSON, XML, binário) sem validar se o resultado é seguro. Um atacante pode injetar código malicioso ou estruturas que exploram o processo de desserialização para executar ações arbitrárias no servidor ou cliente.

Ejemplo

Um serviço Java desserializa um objeto enviado pelo usuário usando ObjectInputStream sem filtros. O atacante envia um payload serializado que, ao ser reconstituído, executa comandos do sistema. Cenário comum: aplicações legadas que confiam em dados de rede ou arquivos sem inspeção.

Cómo mitigar

Valide e filtre dados antes de desserializar — use listas de classes permitidas (whitelisting), implemente validação de schema, e prefira formatos simples (JSON com parse restritivo) em vez de binários com lógica automática. Para linguagens críticas como Java, use bibliotecas seguras ou desabilite gadgets perigosos.

CVE-2023-40044CRITICALWS_FTP Server Ad Hoc Transfer Module .NET Deserialization VulnerabilityEPSS 90.1%KEVCVE-2025-26399CRITICALSolarWinds Web Help Desk Deserialization of Untrusted Data Privilege Escalation VulnerabilityEPSS 89.5%KEVCVE-2018-15381CRITICALCisco Unity Express Arbitrary Command Execution VulnerabilityEPSS 87.3%CVE-2020-10915CRITICALThis vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. AuthenticationEPSS 86.6%CVE-2023-36035HIGHMicrosoft Exchange Server Spoofing VulnerabilityEPSS 86.6%CVE-2022-38111HIGHSolarWinds Platform Deserialization of Untrusted Data VulnerabilityEPSS 84.8%CVE-2024-28986CRITICALSolarWinds Web Help Desk Java Deserialization Remote Code Execution VulnerabilityEPSS 84.6%KEVCVE-2022-36974CRITICALThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authEPSS 84.5%CVE-2025-40551CRITICALSolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution VulnerabilityEPSS 84.2%KEVCVE-2024-30044HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 84.0%CVE-2019-9874CRITICALDeserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 toEPSS 83.7%KEVCVE-2021-42392—The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. EPSS 83.2%CVE-2023-43208CRITICALNextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability iEPSS 82.7%KEVCVE-2021-23758HIGHDeserialization of Untrusted DataEPSS 82.6%KEVCVE-2023-20888HIGHAria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria OEPSS 82.3%CVE-2021-21351MEDIUMXStream is vulnerable to an Arbitrary Code Execution attackEPSS 82.1%CVE-2023-21707HIGHMicrosoft Exchange Server Remote Code Execution VulnerabilityEPSS 82.0%CVE-2020-27868CRITICALThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Qognify Ocularis 5.9.0.395. AuthenticationEPSS 81.8%CVE-2021-42125—An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to EPSS 81.6%CVE-2024-23478HIGHSolarWinds Access Rights Manager (ARM) Deserialization of Untrusted Data Remote Code ExecutionEPSS 81.6%