OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary commands on the targeted system via crafted XML data in a request body.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openmrs | Openmrs | 1.12.0 (including) | 1.12.1 (excluding) |
Openmrs | Openmrs | 2.0.0 (including) | 2.0.8 (excluding) |
Openmrs | Openmrs | 2.1.0 (including) | 2.1.4 (excluding) |