RULE(RULE ID:338404)

Rule General Information
Release Date: 2024-09-10
Rule Name: EOVA doInit Deserialization Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: EOVA is a rapid development framework based on the JFinal development platform , designed to provide efficient , easy-to-use development tools and components to simplify the development process . EOVA has a JDBC deserialization vulnerability, due to the JDBC connection to the mysql server, the parameters are fully controllable , can be passed into the malicious configuration and malicious mysql server address , resulting in a deserialization vulnerability . An attacker can exploit this vulnerability to execute arbitrary commands.
Impact: An attacker can carefully construct malicious serialized data and pass it to the application, and execute the malicious code constructed by the attacker when the application deserializes the object.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.