8.8

CVE-2017-15089

It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.

Data is provided by the National Vulnerability Database (NVD)
InfinispanInfinispan Version <= 9.1.6
InfinispanInfinispan Version9.2.0 Updatealpha1
InfinispanInfinispan Version9.2.0 Updatealpha2
InfinispanInfinispan Version9.2.0 Updatebeta1
InfinispanInfinispan Version9.2.0 Updatebeta2
InfinispanInfinispan Version9.2.0 Updatecr1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.91% 0.879
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.