Miggo Logo

CVE-2023-28935: Apache UIMA DUCC allows remote code execution

8.8

CVSS Score
3.1

Basic Information

EPSS Score
0.66016%
Published
3/30/2023
Updated
4/10/2023
KEV Status
No
Technology
TechnologyJava

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
org.apache.uima:uima-ducc-parentmaven<= 3.0.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

** UNSUPPORT** W**N *SSI*N** ** Improp*r N*utr*liz*tion o* Sp**i*l *l*m*nts us** in * *omm*n* ('*omm*n* Inj**tion') vuln*r**ility in *p**** So*tw*r* *oun**tion *p**** UIM* *U**. W**n usin* t** "*istri*ut** UIM* *lust*r *omputin*" (*U**) mo*ul* o* *p*

Reasoning

No *n*lysis *v*il**l*