Looking for the vulnerability index of Invicti's legacy products?
Jboss EAP Deserialization of Untrusted Data Vulnerability (CVE-2017-7525) - Vulnerability Database

Jboss EAP Deserialization of Untrusted Data Vulnerability (CVE-2017-7525)

Description

A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.

References

Related Vulnerabilities