Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3558

Опубликовано: 16 июл. 2014
Источник: redhat
CVSS2: 3.3
EPSS Низкий

Описание

ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 allows attackers to bypass Java Security Manager (JSM) restrictions and execute restricted reflection calls via a crafted application.

It was discovered that the implementation of org.hibernate.validator.util.ReflectionHelper together with the permissions required to run Hibernate Validator under the Java Security Manager could allow a malicious application deployed in the same application container to execute several actions with escalated privileges, which might otherwise not be possible. This flaw could be used to perform various attacks, including but not restricted to, arbitrary code execution in systems that are otherwise secured by the Java Security Manager.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Virtualization 3rhevm-dependenciesFix deferred
Red Hat JBoss BRMS 5hibernate-validatorWill not fix
Red Hat JBoss Data Grid 6hibernate-validatorFix deferred
Red Hat JBoss Data Virtualization 6hibernate-validatorFix deferred
Red Hat JBoss Enterprise Application Platform 5hibernate3Not affected
Red Hat JBoss Enterprise Application Platform 5hibernate-validatorWill not fix
Red Hat JBoss Enterprise Web Server 1ewpWill not fix
Red Hat JBoss Enterprise Web Server 1fuse-6Affected
Red Hat JBoss Enterprise Web Server 1fuse-esb-7Affected
Red Hat JBoss Enterprise Web Server 1hibernate3Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=1120495Validator: JSM bypass via ReflectionHelper

EPSS

Процентиль: 76%
0.00932
Низкий

3.3 Low

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 allows attackers to bypass Java Security Manager (JSM) restrictions and execute restricted reflection calls via a crafted application.

nvd
больше 11 лет назад

ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 allows attackers to bypass Java Security Manager (JSM) restrictions and execute restricted reflection calls via a crafted application.

debian
больше 11 лет назад

ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hi ...

github
больше 3 лет назад

Improper Authentication in Hibernate Validator

EPSS

Процентиль: 76%
0.00932
Низкий

3.3 Low

CVSS2