HTTP: OpenMRS webservices.rest Insecure Object Deserialization

This signature detects attempts to exploit a known vulnerability against OpenMRS. A successful attack can lead to arbitrary code execution.

Extended Description

OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary commands on the targeted system via crafted XML data in a request body.

Affected Products

Openmrs openmrs

Short Name
HTTP:OPENMRS-INSECURE-DESERIAL
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2018-19276 Deserialization Insecure Object OpenMRS webservices.rest
Release Date
06/10/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Openmrs

CVSS Score

10.0

Found a potential security threat?