Description
Oracle E-Business Suite could allow a remote attacker to execute arbitrary code on the system, caused by a deserialization flaw in iesRuntimeServlet endpoint. By using specially-crafted serialized data, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Remediation
Upgrade to the latest version of Oracle E-Business Suite
References
Related Vulnerabilities
WordPress 5.7.x Multiple Vulnerabilities (5.7 - 5.7.10)
Xdebug remote code execution via xdebug.remote_connect_back
Oracle Business Intelligence AMF Deserialization RCE CVE-2020-2950
Oracle Weblogic Async Component Deserialization RCE CVE-2019-2725
ColdFusion CFC Deserialization RCE (CVE-2023-26359/CVE-2023-26360)