PT-2026-78259 · Splware · Esproc
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SPLWare esProc versions prior to 20260507
Description
An issue exists where performing a manipulation leads to deserialization, which is the process of converting a byte stream back into an object. This occurs within the
ObjectInputStream.readUnshared() function located in the src/main/java/com/scudata/parallel/SocketData.java file, allowing for remote exploitation.Recommendations
Update to a version released after 20260507.
As a temporary workaround, restrict access to the
ObjectInputStream.readUnshared() function to minimize the risk of exploitation.Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Esproc