CVE-2016-0750

Severity
8.8HIGH
EPSS
0.5%
top 32.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 11
Latest updateMay 13

Description

The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:NExploitability: 1.6 | Impact: 2.5

Affected Packages2 packages

CVEListV5red_hat/infinispan9.1.0.Final

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4hhg-8ghq-vwq6: The hotrod java client in infinispan before 92022-05-13
CVEList
CVE-2016-0750: The hotrod java client in infinispan before 92018-09-11

📋Vendor Advisories

1
Red Hat
client: unchecked deserialization in marshaller util2017-11-16

💬Community

1
Bugzilla
CVE-2016-0750 hotrod client: unchecked deserialization in marshaller util2016-01-20
CVE-2016-0750 (HIGH CVSS 8.8) | The hotrod java client in infinispa | cvebase.io