An issue was discovered in UNCTAD ASYCUDA World 2001 through 2020. The Java RMI Server has an Insecure Default Configuration, leading to Java Code Execution from a remote URL because an RMI Distributed Garbage Collector method is called.
Link | Tags |
---|---|
https://unctad.org/en/Pages/DTL/TTL/ASYCUDA-Programme.aspx | product |
https://pastebin.com/jP4thzzG | third party advisory |