CVE-2020-26118

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
11/01/2021
Last modified:
21/07/2021

Description

In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialization vulnerability. The application's UpdateMemento class accepts a serialized Java object directly from the user without properly sanitizing it. A malicious object can be submitted to the server via an authenticated attacker to execute commands on the underlying system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:smartbear:collaborator:*:*:*:*:*:*:*:* 13.3.13302 (including)