漏洞描述 【漏洞对象】JavaMelody 【漏洞描述】JavaMelody是一个用来对java应用进行监控的组件。通过该组件,用户可以以图表形式对内存,cpu,session,sql进行监控。该组件存在未授权访问,可直接查看监控内容,还可做增删改查等敏感操作。
相关漏洞推荐 CVE-2017-12149: Java/Jboss Deserialization [RCE] POC 2025-09-01 | Java Jboss In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was foun... javamelody-detect: JavaMelody Monitoring Exposed POC 2025-09-01 | JavaMelody JavaMelody is a tool used to monitor Java or Java EE applications in QA and production environments.... CVE-2013-3827: Javafaces LFI POC 2025-08-01 | Javafaces An Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.... CVE-2020-10199: Nexus Repository before 3.21.2 allows JavaEL Injection POC 2025-09-01 | Nexus Repository 漏洞触发需要任意账户权限 body="Nexus Repository Manager" app="Nexus-Repository-Manager" LemonLDAP::NG 操作系统命令注入漏洞 无POC 2025-09-20 00:03:21 | LemonLDAP::NG LemonLDAP::NG是LemonLDAP::NG开源的一套Web单点登录和访问管理软件。 LemonLDAP::NG 2.16.7之前版本和2.17版本至2.21.3之前版本存在操作系统命令注入...