CVE-2017-15696

Severity
7.5HIGH
EPSS
0.2%
top 55.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 26
Latest updateMay 14

Description

When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration requests. This allows an unprivileged user who gains access to the Geode locator to extract configuration data and previously deployed application code.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

Mavenorg.apache.geode:geode-core1.0.01.4.0
NVDapache/geode1.0.01.3.0
CVEListV5apache_software_foundation/apache_geodeApache Geode 1.0.0 to 1.3.0

🔴Vulnerability Details

3
OSV
Apache Geode configuration request authorization vulnerability2022-05-14
GHSA
Apache Geode configuration request authorization vulnerability2022-05-14
CVEList
CVE-2017-15696: When an Apache Geode cluster before v12018-02-26
CVE-2017-15696 (HIGH CVSS 7.5) | When an Apache Geode cluster before | cvebase.io