CVE-2019-4279
85Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 9epss 80%
from disclosure to weapon19 days
Published on NVDMay 17
1st PoC+19d
metasploitMay 15
exploitation probability
80%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
In short
IBM WebSphere Application Server versions 8.5 and 9.0 can be tricked into running harmful code when processing specially crafted data from the internet. This allows an attacker to take complete control of the affected server.
Technical detail
The vulnerability exists in unsafe deserialization of untrusted serialized objects in IBM WebSphere Application Server 8.5 and 9.0. A remote attacker can craft malicious serialized payloads to achieve arbitrary code execution with the privileges of the application server process, without requiring prior authentication.
Summary generated and translated by AI from the official description.
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 160445.
CVSS:3.0/S:C/A:H/AC:H/I:H/C:H/AV:N/PR:N/UI:N/RL:O/RC:C/E:U
Affected products
IBM · WebSphere Application Serverpublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/46969⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.