HP ChaiVM EZLoader Arbitrary JAR...

- AV AC AU C I A
发布: 2002-07-27
修订: 2025-04-13

ChaiVM is the Chai Virtual Machine. The ChaiServer is a component of the ChaiVM infrastructure. It is distributed and maintained by Hewlett-Packard. The EZLoader does not sufficiently validate JAR signatures of services prior to loading them. Because of this, a user with access to the local system may be able to load unauthorized services of questionable origin via the ChaiServer. This could allow a user to remove a legitimate service from the ChaiServer, and replace it with a malicious version of the original service.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息