All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://snyk.io/vuln/SNYK-JAVA-COMBSTEKUREPORT-2322018 | third party advisory |
https://github.com/JinYiTong/CVE-Req/blob/main/ureport2/ureport2-console.md | third party advisory exploit |