'; } else{ echo ''; } echo '
|
|
|||
| Rule General Information |
|---|
| Release Date: | 2025-10-22 | |
| Rule Name: | FineReport API channel Deserialization Vulnerability | |
| Severity: | ||
| CVE ID: | ||
| Rule Protection Details |
|---|
| Description: | FineReport reporting software is an enterprise-level web reporting tool written purely in Java, integrating the functions of data display reports and data entry forms. The channel interface of the FineReport has a deserialization vulnerability. Attackers can use this vulnerability to send maliciously constructed serialized data to execute remote code and gain control of the server. | |
| Impact: | An attacker can carefully construct malicious serialized data and pass it to the application, and execute the malicious code constructed by the attacker when the application deserializes the object. | |
| Affected OS: | Windows, Linux, Others | |
| Reference: | ||
| Solutions |
|---|
| Please contact the software vendor to update the software patch. |