CVE-2020-26118
In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialization vulnerability.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.76%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialization vulnerability. The application's UpdateMemento class accepts a serialized Java object directly from the user without properly sanitizing it. A malicious object can be submitted to the server via an authenticated attacker to execute commands on the underlying system.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.76% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- smartbear/collaborator
- Source
- cve@mitre.org
References
- https://support.smartbear.com/collaborator/docs/general-info/version-history/ver-13/ver-13-0.htmlRelease Notes, Vendor Advisory
- https://support.smartbear.com/collaborator/docs/general-info/whats-new.htmlRelease Notes, Vendor Advisory
- https://support.smartbear.com/collaborator/docs/server/index.htmlProduct, Vendor Advisory
- https://support.smartbear.com/collaborator/docs/general-info/version-history/ver-13/ver-13-0.htmlRelease Notes, Vendor Advisory
- https://support.smartbear.com/collaborator/docs/general-info/whats-new.htmlRelease Notes, Vendor Advisory
- https://support.smartbear.com/collaborator/docs/server/index.htmlProduct, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.