CVE-2016-0750
published 2018-09-11CVE-2016-0750: The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit…
PriorityP353high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
2.40%
82.2th percentile
The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| infinispan | infinispan | < 9.1.0 | 9.1.0 |
| red_hat | infinispan | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Infinispan: Deserialization of untrusted data in the Hot Rod Java client via automatic byte-array deserialization
ghsa·2022-05-13
CVE-2016-0750 [HIGH] CWE-502 Infinispan: Deserialization of untrusted data in the Hot Rod Java client via automatic byte-array deserialization
Infinispan: Deserialization of untrusted data in the Hot Rod Java client via automatic byte-array deserialization
The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks.
GHSA
GHSA-4hhg-8ghq-vwq6: The hotrod java client in infinispan before 9
ghsa_unreviewed·2022-05-13
CVE-2016-0750 [HIGH] CWE-502 GHSA-4hhg-8ghq-vwq6: The hotrod java client in infinispan before 9
The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks.
Red Hat
client: unchecked deserialization in marshaller util
vendor_redhat·2017-11-16·CVSS 4.2
CVE-2016-0750 [MEDIUM] CWE-138 client: unchecked deserialization in marshaller util
client: unchecked deserialization in marshaller util
The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks.
The hotrod java client in infinispan automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks.
Package: hotrod-client (Red Hat JBoss Data Grid 6) - Under investigation
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/101910https://access.redhat.com/errata/RHSA-2017:3244https://access.redhat.com/errata/RHSA-2018:0501https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-0750https://github.com/infinispan/infinispan/pull/5116https://issues.jboss.org/browse/ISPN-7781http://www.securityfocus.com/bid/101910https://access.redhat.com/errata/RHSA-2017:3244https://access.redhat.com/errata/RHSA-2018:0501https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-0750https://github.com/infinispan/infinispan/pull/5116https://issues.jboss.org/browse/ISPN-7781
2018-09-11
Published