CVE-2017-15089

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
15/02/2018
Last modified:
04/06/2019

Description

It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:infinispan:infinispan:*:*:*:*:*:*:*:* 9.1.6 (including)
cpe:2.3:a:infinispan:infinispan:9.2.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:infinispan:infinispan:9.2.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:infinispan:infinispan:9.2.0:beta1:*:*:*:*:*:*
cpe:2.3:a:infinispan:infinispan:9.2.0:beta2:*:*:*:*:*:*
cpe:2.3:a:infinispan:infinispan:9.2.0:cr1:*:*:*:*:*:*