CVE-2016-9045: High severity processmaker pm4 core docker vulnerability
Published Sep 17, 2018
·Updated
A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker can send a crafted web parameter to trigger this vulnerability.
Affected Software
1 affected component
ProcessMaker ProcessMaker=3.0.1.7
Event History
Sep 17, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-9045?
CVE-2016-9045 is considered critical due to its potential for remote code execution.
2
How do I fix CVE-2016-9045?
To mitigate CVE-2016-9045, upgrade ProcessMaker Enterprise Core to a version that includes patches for this vulnerability.
3
What software is affected by CVE-2016-9045?
CVE-2016-9045 affects ProcessMaker Enterprise Core version 3.0.1.7.
4
What type of vulnerability is CVE-2016-9045?
CVE-2016-9045 is a code execution vulnerability caused by unsafe deserialization.
5
How can an attacker exploit CVE-2016-9045?
An attacker can exploit CVE-2016-9045 by sending a specially crafted web request with malicious parameters.