Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-0750

Опубликовано: 16 нояб. 2017
Источник: redhat
CVSS3: 4.2
CVSS2: 3.6
EPSS Низкий

Описание

The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks.

The hotrod java client in infinispan automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Data Grid 6hotrod-clientUnder investigation
Red Hat JBoss Data Grid 7.1FixedRHSA-2017:324416.11.2017
Red Hat Single Sign-On 7.2.1 zipFixedRHSA-2018:050113.03.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-138
https://bugzilla.redhat.com/show_bug.cgi?id=1300443client: unchecked deserialization in marshaller util

EPSS

Процентиль: 68%
0.00556
Низкий

4.2 Medium

CVSS3

3.6 Low

CVSS2

Связанные уязвимости

CVSS3: 4.2
nvd
больше 7 лет назад

The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks.

CVSS3: 8.8
github
больше 3 лет назад

The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks.

EPSS

Процентиль: 68%
0.00556
Низкий

4.2 Medium

CVSS3

3.6 Low

CVSS2