1 results (0.001 seconds)

CVSS: 7.5EPSS: 2%CPEs: 7EXPL: 0

21 Dec 2015 — Serialized-object interfaces in VMware vRealize Orchestrator 6.x, vCenter Orchestrator 5.x, vRealize Operations 6.x, vCenter Operations 5.x, and vCenter Application Discovery Manager (vADM) 7.x allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library. Interfaces objeto-serializado en VMware vRealize Orchestrator 6.x, vCenter Orchestrator 5.x, vRealize Operations 6.x, vCenter Operations 5.x y vCenter Application Discovery Man... • http://www.securityfocus.com/bid/79648 • CWE-20: Improper Input Validation •