CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. It affects Apache, Java. Its EPSS score suggests a 35.3% probability of exploitation in the next 30 days.
CVE
CVE-2019-17564
Severity
CRITICAL
CVSS
9.8
EPSS
35.32%
Apache Java
Original NVD Description
Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables HTTP. This issue affected Apache Dubbo 2.7.0 to 2.7.4, 2.6.0 to 2.6.7, and all 2.5.x versions.
Related CVEs
Other vulnerabilities affecting the same vendor(s)