CVE-2019-17564
/
CX-2020-4275
Advisories
Disclosure Policy
Contact Us
Check with SCA
Defend your code against
SpringShell
in two ways: read our
blog post
with what-to-do advice, and use
Checkmarx SCA
to test your applications.
9.8
Critical
Severity
Critical Severity
9.8
CVE-2019-17564
/
CX-2020-4275
/ State: Published
Unsafe deserialization in Apache Dubbo
java
apache
rce
unsafe deserialization
Dor Tumarkin
Feb 10, 2020
Details
Overview
9.8
Critical
Severity
Critical Severity
9.8
Properties
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Confidentiality:
High
Integrity:
High
Availability:
High
Advisory Timeline
Discovered
Aug 13, 2019
Fixed
Dec 29, 2019
CVE released
Feb 11, 2020
Published
Feb 10, 2020
Stay up to date with our newsletter
Subscribe
/advisory/CX-2020-4275/