CVE-2017-9830
Remote Code Execution is possible in Code42 CrashPlan 5.4.x via the org.apache.commons.ssl.rmi.DateRMI Java class, because (upon instantiation) it creates an RMI server that listens on a TCP port and deserializes objects sent by TCP clients.
- Affected products
- Apache Commons
- code42 Crashplan
- = 5.4
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 6.5% (93th percentile)
- Weakness
- CWE-502
- NVD status
- Modified
- Published
- 2017-06-27
CVE-2017-9830 at NVD
2 known exploits for CVE-2017-9830
Proof-of-concept code and exploit modules indexed by Sploitus