An issue was discovered in RWS WorldServer before 11.7.3. /clientLogin deserializes Java objects without authentication, leading to command execution on the host.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://www.rws.com/localization/products/trados-enterprise/worldserver/ | product |
https://www.triskelelabs.com/vulnerabilities-in-rws-worldserver | third party advisory exploit |