CVE-2017-15089
published 2018-02-15CVE-2017-15089: It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated…
PriorityP346high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
2.88%
85.3th percentile
It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| infinispan | infinispan | <= 9.1.6 | — |
| infinispan | infinispan | — | — |
| infinispan | infinispan | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Deserialization of Untrusted Data in Infinispan
osv·2022-05-14
CVE-2017-15089 [HIGH] Deserialization of Untrusted Data in Infinispan
Deserialization of Untrusted Data in Infinispan
It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.
GHSA
Deserialization of Untrusted Data in Infinispan
ghsa·2022-05-14
CVE-2017-15089 [HIGH] CWE-502 Deserialization of Untrusted Data in Infinispan
Deserialization of Untrusted Data in Infinispan
It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.
Red Hat
infinispan: Unsafe deserialization of malicious object injected into data cache
vendor_redhat·2018-02-12·CVSS 8.8
CVE-2017-15089 [HIGH] CWE-502 infinispan: Unsafe deserialization of malicious object injected into data cache
infinispan: Unsafe deserialization of malicious object injected into data cache
It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.
It was found that the Hotrod client in Infinispan would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.
Package: infinispan-core (Red Hat JBoss Data Grid 6) - Will not fix
Package: infinispan-core (Red Hat JBoss Data Virtualization 6) - Not affected
No detection rules found.
No public exploits indexed.
http://www.securitytracker.com/id/1040360https://access.redhat.com/errata/RHSA-2018:0294https://access.redhat.com/errata/RHSA-2018:0478https://access.redhat.com/errata/RHSA-2018:0479https://access.redhat.com/errata/RHSA-2018:0480https://access.redhat.com/errata/RHSA-2018:0481https://access.redhat.com/errata/RHSA-2018:0501https://access.redhat.com/errata/RHSA-2019:1326https://github.com/infinispan/infinispan/pull/5639http://www.securitytracker.com/id/1040360https://access.redhat.com/errata/RHSA-2018:0294https://access.redhat.com/errata/RHSA-2018:0478https://access.redhat.com/errata/RHSA-2018:0479https://access.redhat.com/errata/RHSA-2018:0480https://access.redhat.com/errata/RHSA-2018:0481https://access.redhat.com/errata/RHSA-2018:0501https://access.redhat.com/errata/RHSA-2019:1326https://github.com/infinispan/infinispan/pull/5639
2018-02-15
Published