Lexmark Markvision Enterprise before 2.3.0 misuses the Apache Commons Collections Library, leading to remote code execution because of Java deserialization.
References
Link | Resource |
---|---|
http://support.lexmark.com/index?page=content&id=TE747&locale=EN&userlocale=EN_US | Vendor Advisory |
http://support.lexmark.com/index?page=content&id=TE747&locale=EN&userlocale=EN_US | Vendor Advisory |
Configurations
History
21 Nov 2024, 02:46
Type | Values Removed | Values Added |
---|---|---|
References | () http://support.lexmark.com/index?page=content&id=TE747&locale=EN&userlocale=EN_US - Vendor Advisory |
Information
Published : 2020-03-09 19:15
Updated : 2024-11-21 02:46
NVD link : CVE-2016-1487
Mitre link : CVE-2016-1487
CVE.ORG link : CVE-2016-1487
JSON object : View
Products Affected
lexmark
- markvision_enterprise
CWE
CWE-502
Deserialization of Untrusted Data