Input validation error in Fastjson - #VU23397

 

Input validation error in Fastjson - #VU23397

Published: December 4, 2019 / Updated: May 23, 2022


Vulnerability identifier: #VU23397
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted JSON data packets and execute arbitrary code on the target Fastjson server.


Affected software

Fastjson
FusionCompute
eSpace ECS
iManager NetEco 6000
iManager NetEco
RSE6500

Remediation

Install update from vendor's website.

FusionCompute - update to 8.0
RSE6500 - update to V500R002C00SPCh00
eSpace ECS - update to V300R001C00SPC221
iManager NetEco 6000 - update to V600R008C10SPC540
iManager NetEco - update to V600R008C30CP2402

External References

Related Security Bulletins