← back
CVE-2019-4279critical

CVE-2019-4279

85Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 9epss 80%
from disclosure to weapon19 days
Published on NVDMay 17
1st PoC+19d
metasploitMay 15
exploitation probability
80%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
In short

IBM WebSphere Application Server versions 8.5 and 9.0 can be tricked into running harmful code when processing specially crafted data from the internet. This allows an attacker to take complete control of the affected server.

Technical detail

The vulnerability exists in unsafe deserialization of untrusted serialized objects in IBM WebSphere Application Server 8.5 and 9.0. A remote attacker can craft malicious serialized payloads to achieve arbitrary code execution with the privileges of the application server process, without requiring prior authentication.

Summary generated and translated by AI from the official description.
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 160445.
CVSS:3.0/S:C/A:H/AC:H/I:H/C:H/AV:N/PR:N/UI:N/RL:O/RC:C/E:U
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.