CVE-2016-10750

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
22/05/2019
Last modified:
08/08/2019

Description

In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a listening Hazelcast instance with a crafted JoinRequest, and vulnerable classes exist in the classpath, the attacker can run arbitrary code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hazelcast:hazelcast:*:*:*:*:*:*:*:* 3.11 (excluding)