CVE-2019-17570
CRITICAL 9.8EPSS 49.3%
An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue will not be fixed.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 49.29% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2020-01-23
- Updated
- 2024-08-05
Proof-of-concept exploits (4)
- orangecertcc/security-research/security/advisories/GHSA-x2r6-4m45-m4jp
- r00t4dm/CVE-2019-175704★ · 2020-06-15
- slowmistio/xmlrpc-common-deserialization0★ · 2020-01-24
- im23pds/xmlrpc-common-deserialization