Home
CRITICAL: 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 15.0.4
affected
Description
SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from the new GINA UI and may allow unauthenticated remote attackers to execute code via a crafted serialized object.
Problem types
CWE-502 Deserialization of untrusted data
Product status
Any version before 15.0.4
References
downloads.seppmail.com/extrelnotes/150/ERN15.0.html