Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2022-34268
Disclosure Date: December 25, 2023 (last updated January 04, 2024)
An issue was discovered in RWS WorldServer before 11.7.3. /clientLogin deserializes Java objects without authentication, leading to command execution on the host.
0
Attacker Value
Unknown
CVE-2022-34267
Disclosure Date: December 25, 2023 (last updated January 04, 2024)
An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arbitrary Java code can be uploaded and executed via a .jar archive to the ws-api/v2/customizations/api endpoint.
0
Attacker Value
Unknown
CVE-2023-38357
Disclosure Date: August 01, 2023 (last updated October 08, 2023)
Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized access to user sessions.
0