WebORB for Java is prone to a remote code execution vulnerability and an XML External Entity injection vulnerability.
Successfully exploiting this issue allows attackers to execute arbitrary code in the context of the affected application, to gain access to sensitive information or cause denial-of-service conditions.
WebORB for Java 5.1.1.0 is vulnerable; other versions may also be affected.
Information
CVE-2017-3208
References:
- AMF â?? Another Malicious Format (Codewhitesec)
- MidnightCoders Homepage (MidnightCoders)
- VU#307983: AMF3 Java implementations are vulnerable to insecure deserialization (CERT)