← nejvýznamnější zprávy · všechny zprávy

EPSS 0.01

iba: Deserialization vulnerability in ibaPDA and ibaDatCoordinator

[VDE-2026-051] A vulnerability has been identified in ibaPDA, ibaDatCoordinator and ibaLogic. The affected applications do not properly restrict the .NET BinaryFormatter when deserializing client-server input. This could allow an attacker to cause a type confusion and execute arbitrary code within the affected applications. This is the same issue that exists for the .NET BinaryFormatter: https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300.

Číst originál na CERT@VDE →

1 zpráva z 1 zdroje · první 2. 9. 14:00 · poslední 2. 9. 14:00 CZ · EN/orig

iba DE

tg: zranitelnost

CVE v události 1

CVEhodnoceníKEVEPSS
CVE-2026-8024 9.8 3.1 · CERTVDE 9.3 4.0 · CERTVDE 0.01

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.

Jak se o tom psalo 1

  1. · CERT@VDE DE nadpis události

    iba: Deserialization vulnerability in ibaPDA and ibaDatCoordinator

    [VDE-2026-051] A vulnerability has been identified in ibaPDA, ibaDatCoordinator and ibaLogic. The affected applications do not properly restrict the .NET BinaryFormatter when deserializing client-server input. This could allow an attacker to cause a type confusion and execute arbitrary code within the affected applications. This is the same issue that exists for the .NET BinaryFormatter: https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300.