{"id":"CVE-2019-9212","aliases":["GHSA-pfwp-8pq4-g7pv"],"url":"https://o3.security/vulnerability/CVE-2019-9212","summary":"Incomplete List of Disallowed Inputs in SOFA-Hessian","details":"SOFA-Hessian through 4.0.2 allows remote attackers to execute arbitrary commands via a crafted serialized Hessian object because blacklisting of com.caucho.naming.QName and com.sun.org.apache.xpath.internal.objects.XString is mishandled, related to Resin Gadget. NOTE: The vendor doesn’t consider this issue a vulnerability because the blacklist is being misused. SOFA Hessian supports custom blacklist and a disclaimer was posted encouraging users to update the blacklist or to use the whitelist feature for their specific needs since the blacklist is not being actively updated","published":"2019-02-27T17:29:00.427Z","modified":"2026-07-08T16:28:48.205096Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Maven","name":"com.alipay.sofa:hessian","fixedVersion":"4.0.2"},{"ecosystem":"Maven","name":"com.alipay.sofa:hessian","fixedVersion":"3.3.6"}],"fix":null,"references":[{"type":"FIX","url":"https://github.com/alipay/sofa-hessian/issues/34"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T16:28:48.205096Z"}}