Description
SolarWinds Web Help Desk has a Java object deserialization vulnerability (based on the detected version). An unauthenticated attacker could send a specially crafted serialized request to execute arbitrary code on the system.
Remediation
Upgrade to the latest version of SolarWinds Web Help Desk.
References
Related Vulnerabilities
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-46243)
Dolibarr Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-11201)
Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-14820)
TYPO3 Cleartext Transmission of Sensitive Information Vulnerability (CVE-2022-31046)