Vulnerability Description
Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product allows a remote attacker to inject unsecure serialized Java object using a specially crafted HTTP request, resulting in an unauthenticated remote code execution on the server.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aca | Assuweb | 359.3 |
Related Weaknesses (CWE)
References
- https://www.aca.fr/solution/assurex-solution-gestion-des-contrats-assurance/Vendor Advisory
- https://www.digital.security/fr/sites/default/files/advisories/cert-ds_advisory_Third Party Advisory
- https://www.aca.fr/solution/assurex-solution-gestion-des-contrats-assurance/Vendor Advisory
- https://www.digital.security/fr/sites/default/files/advisories/cert-ds_advisory_Third Party Advisory
FAQ
What is CVE-2021-3160?
CVE-2021-3160 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product allows a remote attacker to inject unsecure serialized Java object using a speci...
How severe is CVE-2021-3160?
CVE-2021-3160 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-3160?
Check the references section above for vendor advisories and patch information. Affected products include: Aca Assuweb.