Security advisory: Pre-authentication RCE (default credentials) in ObjectDB 2.9.5 server mode (ObjectDB Software)
Posted by disclosure via Fulldisclosure on Aug 170day Rubbish Research Team is publicly disclosing a vulnerability in ObjectDB 2.9.5 server mode (ObjectDB Software).
The research is published and a proof-of-concept is available. Pre-authentication RCE (default credentials) (CVSS 9.8, pre-authentication) ObjectDB 2.9.5 server mode (port 6136, proprietary binary protocol) has a critical remote code execution vulnerability:
JDOQL query filter evaluation allows arbitrary static-method...