
Cloud Vulnerability DB
A community-led vulnerabilities database
In SmartBear Collaborator Server through 13.3.13302, a post-authentication Java deserialization vulnerability exists in the Google Web Toolkit (GWT) API implementation. The vulnerability was disclosed on January 11, 2021. The application's UpdateMemento class accepts serialized Java objects from authenticated users without proper sanitization (NVD).
The vulnerability is related to improper handling of serialized Java objects in the UpdateMemento class. The CVSS v3.1 base score is 8.8 (HIGH) with vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The vulnerability is classified as CWE-502: Deserialization of Untrusted Data (NVD).
If exploited, this vulnerability allows authenticated attackers to execute commands on the underlying system through submission of malicious serialized Java objects (NVD).
The vulnerability requires authentication to exploit, as it is a post-authentication vulnerability. An authenticated attacker can submit malicious serialized Java objects to execute commands on the system (NVD).
The vulnerability affects SmartBear Collaborator Server versions through 13.3.13302. Users should upgrade to a patched version of the software (SmartBear Release Notes).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."