CVE-2022-37027

CVE-2022-37027

Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime Options in the web interface can inject Java Runtime Options. These take effect after a restart. For example, an attacker can enable JMX services and consequently achieve remote code execution as the system user.

Source: CVE-2022-37027

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다