CVE-2019-16112

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
13/05/2020
Last modified:
15/05/2020

Description

TylerTech Eagle 2018.3.11 deserializes untrusted user input, resulting in remote code execution via a crafted Java object to the recorder/ServiceManager?service=tyler.empire.settings.SettingManager URI.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tylertech:eagle:2018.3.11:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools