First published: Tue Apr 05 2022(Updated: )
The HTTP client in MashZone NextGen through 10.7 GA deserializes untrusted data when it gets an HTTP response with a 570 status code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Softwareag Mashzone Nextgen | <=10.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33207 is a critical vulnerability in MashZone NextGen software that allows the deserialization of untrusted data when receiving a HTTP response with a 570 status code.
CVE-2021-33207 has a severity rating of 9.8 (critical).
CVE-2021-33207 affects MashZone NextGen versions up to and including 10.7 GA.
By exploiting CVE-2021-33207, an attacker can execute arbitrary code or perform Denial of Service (DoS) attacks on vulnerable MashZone NextGen installations.
To fix CVE-2021-33207, it is recommended to upgrade MashZone NextGen to version 10.8 or apply the necessary patches provided by SoftwareAG.