Vulnerability CVE-2017-5983


Published: 2017-04-10

Description:
The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Atlassian -> JIRA 

 References:
http://codewhitesec.blogspot.com/2017/04/amf.html
http://www.securityfocus.com/bid/97379
https://confluence.atlassian.com/jira063/jira-security-advisory-2017-03-09-875604401.html
https://jira.atlassian.com/browse/JRASERVER-64077
https://www.kb.cert.org/vuls/id/307983

Copyright 2024, cxsecurity.com

 

Back to Top