An issue found in MIM software Inc MIM License Server and MIMpacs services v.6.9 thru v.7.0 fixed in v.7.0.10 allows a remote unauthenticated attacker to execute arbitrary code via the RMI Registry service.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://www.mimsoftware.com/ | product |
https://www.kansashealthsystem.com/ | not applicable |
https://www.mimsoftware.com/cve-2023-30262 | patch vendor advisory mitigation |