Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
http://openmeetings.markmail.org/thread/tr47byaaopnemvne | third party advisory mailing list |
http://www.securityfocus.com/bid/94145 | vdb entry third party advisory |