8.8

CVE-2019-10174

A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Infinispan ≫ Infinispan Version < 8.2.12
Infinispan ≫ Infinispan Version >= 9.0.0 < 9.4.17
Redhat ≫ Fuse Version 1.0
Redhat ≫ Jboss Data Grid Version - SwEdition text-only
Redhat ≫ Jboss Enterprise Application Platform Version - SwEdition text-only
Redhat ≫ Openshift Application Runtimes Version - SwEdition text-only
Redhat ≫ Single Sign-on Version - SwEdition text-only
Redhat ≫ Jboss Enterprise Application Platform Version 7.2
   Redhat ≫ Enterprise Linux Version 6.0
   Redhat ≫ Enterprise Linux Version 7.0
   Redhat ≫ Enterprise Linux Version 8.0
Netapp ≫ Active Iq Unified Manager Version - SwPlatform linux
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Netapp ≫ Active Iq Unified Manager Version - SwPlatform windows
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.09% 0.86
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat 7.5 1.6 5.9
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.

https://access.redhat.com/errata/RHSA-2020:0481
Vendor Advisory
https://access.redhat.com/errata/RHSA-2020:0727
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10174
Vendor Advisory
Issue Tracking
https://security.netapp.com/advisory/ntap-20220210-0018/
Third Party Advisory