MSFM Deserialization Vulnerability in pom.xml Configuration File

Vulnerability

A deserialization vulnerability has been identified in MSFM versions prior to 2025.01.01. This issue arises from the application's handling of the pom.xml configuration file, which can be exploited to manipulate object serialization processes.

Impact

Exploitation of this vulnerability allows for arbitrary code execution, as the application deserializes untrusted data without proper validation, potentially leading to the execution of malicious payloads.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.