[0day-rubbish] Accurate Online Private Cloud on-prem (current) Unauthenticated Hessian deserialization leading to JNDI remote class loading (9.8)
0day Rubbish disclosed an unauthenticated Hessian deserialization flaw in Accurate Online Private Cloud on-prem allowing JNDI remote class loading, rated 9.8.
The 0day Rubbish Research Team publicly disclosed an unauthenticated Hessian deserialization vulnerability in the current on-premises release of Accurate Online Private Cloud. The flaw lets unauthenticated attackers trigger JNDI remote class loading, a path that typically yields remote code execution. The issue carries a CVSS 9.8 rating. No CVE identifier or evidence of in-the-wild exploitation was included in the disclosure.
- Unauthenticated Hessian deserialization reachable without credentials
- Enables JNDI remote class loading and likely RCE
- Rated CVSS 9.8 (network vector, low complexity)
- Publicly disclosed by 0day Rubbish Research Team
Posted by disclosure via Fulldisclosure on Sep 08 TO: fulldisclosure () seclists org SUBJECT: [0day-rubbish] Accurate Online Private Cloud on-prem (current) Unauthenticated Hessian deserialization leading to JNDI remote class loading (9.8) FROM: disclosure () 0day-rubbish com ----BODY---- 0day Rubbish Research Team is publicly disclosing a vulnerability in Accurate Online Private Cloud on-prem (current). Type: Unauthenticated Hessian deserialization leading to JNDI remote class loading...
This source does not provide full text. Read it at seclists.org.