Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL loading of Java MBeans, which allows remote attackers to execute arbitrary Java code by registering MBeans.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Aternity Web服务器安全漏洞
Vulnerability Description
Aternity webserver是美国Aternity公司的一款Web服务器。 Aternity 9及之前版本中的Web服务器存在安全漏洞,该漏洞源于程序没有对getMBeansFromURL下载Java Mbeans要求身份验证。远程攻击者可通过注册Mbeans利用该漏洞执行任意Java代码。
CVSS Information
N/A
Vulnerability Type
N/A