back to article Progress discloses second critical flaw in Telerik Report Server in as many months

Progress Software's latest security advisory warns customers about the second critical vulnerability targeting its Telerik Report Server in as many months. CVE-2024-6327 is an insecure deserialization vulnerability (CWE-502) carrying a 9.9 CVSS score. Successful exploits can lead to remote code execution (RCE) on servers …

  1. Anonymous Coward
    Boffin

    Insecure deserialization vulnerability

    By default, serialization/serialization doesn't provide any validation or security. A zipped-up applet send over an insecure channel to the client. As such it can be intercepted and/or altered. As such, a bit of a design fault.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like