cbcvebase.
CVE-2017-15692
published 2018-02-27

CVE-2017-15692: In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains access to the…

PriorityP358critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.87%
91.0th percentile
In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains access to the Geode locator, they may be able to cause remote code execution if certain classes are present on the classpath.

Affected

2 ranges
VendorProductVersion rangeFixed in
apachegeode< 1.4.01.4.0
apache_software_foundationapache_geode

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.