Description
Oracle E-Business Suite could allow a remote attacker to execute arbitrary code on the system, caused by a deserialization flaw in iesRuntimeServlet endpoint. By using specially-crafted serialized data, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Remediation
Upgrade to the latest version of Oracle E-Business Suite
References
Related Vulnerabilities
WordPress 4.8.x Multiple Vulnerabilities (4.8 - 4.8.14)
Apache OFBiz XMLRPC Deserialization RCE (CVE-2020-9496/CVE-2023-49070)
WordPress 6.2.x Multiple Vulnerabilities (6.2 - 6.2.3)
Apache Log4j socket receiver deserialization vulnerability
Oracle Business Intelligence AMF Deserialization RCE CVE-2020-2950