Falhas do tipo CWE-502

2.373 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2018-1000861CRITICALA code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/corEPSS 98.3%KEVCVE-2021-39144HIGHXStream is vulnerable to a Remote Command Execution attackEPSS 98.1%KEVCVE-2021-42237CRITICALSitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achiEPSS 97.9%KEVCVE-2025-49113CRITICALRoundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in aEPSS 97.7%KEVCVE-2015-7450CRITICALSerialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products alloEPSS 97.7%KEVCVE-2020-2555CRITICALVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions thaEPSS 97.1%KEVCVE-2023-38203CRITICALAnalysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCEEPSS 96.5%KEVCVE-2015-4852CRITICALThe WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitraryEPSS 96.0%KEVCVE-2019-10068CRITICALAn issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure tEPSS 96.0%KEVCVE-2023-25194HIGHApache Kafka Connect API: Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration using Kafka Connect EPSS 95.8%CVE-2021-31474CRITICALThis vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 202EPSS 94.4%CVE-2021-26857HIGHMicrosoft Exchange Server Remote Code Execution VulnerabilityEPSS 94.0%KEVCVE-2025-24016CRITICALRemote code execution in Wazuh serverEPSS 93.8%KEVCVE-2021-27850Bypass of the fix for CVE-2019-0195EPSS 93.8%CVE-2024-0692HIGHSolarWinds Security Event Manager Deserialization of Untrusted Data Remote Code Execution VulnerabilityEPSS 92.2%CVE-2019-6340HIGHDrupal core - Highly critical - Remote Code ExecutionEPSS 92.0%KEVCVE-2017-12149CRITICALIn Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnEPSS 90.7%KEVCVE-2017-3066CRITICALAdobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserializaEPSS 90.6%KEVCVE-2024-40711CRITICALA deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).EPSS 90.4%KEVCVE-2023-40044CRITICALWS_FTP Server Ad Hoc Transfer Module .NET Deserialization VulnerabilityEPSS 90.1%KEV