CVE-2018-19276

OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary commands on the targeted system via crafted XML data in a request body.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openmrs:openmrs:*:*:*:*:*:*:*:*
cpe:2.3:a:openmrs:openmrs:*:*:*:*:*:*:*:*
cpe:2.3:a:openmrs:openmrs:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:57

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/151553/OpenMRS-Platform-Insecure-Object-Deserialization.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/151553/OpenMRS-Platform-Insecure-Object-Deserialization.html - Exploit, Third Party Advisory, VDB Entry
References () http://packetstormsecurity.com/files/155691/OpenMRS-Java-Deserialization-Remote-Code-Execution.html - Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/155691/OpenMRS-Java-Deserialization-Remote-Code-Execution.html - Third Party Advisory, VDB Entry
References () https://know.bishopfox.com/advisories/news/2019/02/openmrs-insecure-object-deserialization - Third Party Advisory () https://know.bishopfox.com/advisories/news/2019/02/openmrs-insecure-object-deserialization - Third Party Advisory
References () https://talk.openmrs.org/t/critical-security-advisory-cve-2018-19276-2019-02-04/21607 - Vendor Advisory () https://talk.openmrs.org/t/critical-security-advisory-cve-2018-19276-2019-02-04/21607 - Vendor Advisory
References () https://www.exploit-db.com/exploits/46327/ - Exploit, VDB Entry, Third Party Advisory () https://www.exploit-db.com/exploits/46327/ - Exploit, Third Party Advisory, VDB Entry

Information

Published : 2019-03-21 16:00

Updated : 2024-11-21 03:57


NVD link : CVE-2018-19276

Mitre link : CVE-2018-19276

CVE.ORG link : CVE-2018-19276


JSON object : View

Products Affected

openmrs

  • openmrs
CWE
CWE-502

Deserialization of Untrusted Data