// For flags

CVE-2013-4521

 

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data. NOTE: this vulnerability may overlap CVE-2013-2165.

La implementación de RichFaces en Nuxeo Platform versión 5.6.0 anterior a HF27 y versión 5.8.0 anterior a HF-01, no restringe las clases para las que los métodos de deserialización pueden ser llamados, lo que permite a atacantes remotos ejecutar código arbitrario por medio de datos serializados diseñados. NOTA: esta vulnerabilidad puede solaparse con CVE-2013-2165.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-06-12 CVE Reserved
  • 2020-02-06 CVE Published
  • 2023-04-09 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-502: Deserialization of Untrusted Data
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
-
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix01
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix02
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix03
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix04
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix05
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix06
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix07
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix08
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix09
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix10
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix11
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix12
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix13
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix14
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix15
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix16
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix17
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix18
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix19
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix20
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix21
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix22
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix23
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix24
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix25
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.6.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.6.0"
hotfix26
Affected
Nuxeo
Search vendor "Nuxeo"
Nuxeo
Search vendor "Nuxeo" for product "Nuxeo"
5.8.0
Search vendor "Nuxeo" for product "Nuxeo" and version "5.8.0"
-
Affected