QID 980665
QID 980665: Java (maven) Security Update for org.apache.xmlrpc:xmlrpc (GHSA-6vwp-35w3-xph8)
An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code.
Apache XML-RPC is no longer maintained and this issue will not be fixed.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-6vwp-35w3-xph8 for updates pertaining to this vulnerability.
Vendor References
- GHSA-6vwp-35w3-xph8 -
github.com/advisories/GHSA-6vwp-35w3-xph8
CVEs related to QID 980665
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6vwp-35w3-xph8 | org.apache.xmlrpc:xmlrpc |
|