Page 2 of 7 results (0.010 seconds)

CVSS: 8.8EPSS: 1%CPEs: 1EXPL: 0

The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks. El cliente de Java hotrod en infinispan en versiones anteriores a la 9.1.0.Final deserializa automáticamente el contenido de los mensajes bytearray en ciertos eventos. Un usuario malicioso podría explotar este error inyectando un objeto serializado especialmente manipulado para lograr la ejecución remota de código u otros ataques. The hotrod java client in infinispan automatically deserializes bytearray message contents in certain events. • http://www.securityfocus.com/bid/101910 https://access.redhat.com/errata/RHSA-2017:3244 https://access.redhat.com/errata/RHSA-2018:0501 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-0750 https://github.com/infinispan/infinispan/pull/5116 https://issues.jboss.org/browse/ISPN-7781 https://access.redhat.com/security/cve/CVE-2016-0750 https://bugzilla.redhat.com/show_bug.cgi?id=1300443 • CWE-138: Improper Neutralization of Special Elements CWE-502: Deserialization of Untrusted Data •

CVSS: 6.5EPSS: 0%CPEs: 2EXPL: 0

It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name. Se ha descubierto que la API REST en Infinispan en versiones anteriores a la 9.0.0 no aplicaba correctamente las restricciones auth. Un atacante podría emplear esta vulnerabilidad para leer o modificar datos en la caché por defecto o un nombre de caché conocido. It was found that the REST API in infinispan did not properly enforce auth constraints. • http://rhn.redhat.com/errata/RHSA-2017-1097.html http://www.securityfocus.com/bid/97964 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2638 https://github.com/infinispan/infinispan/pull/4936/commits https://issues.jboss.org/browse/ISPN-7485 https://access.redhat.com/security/cve/CVE-2017-2638 https://bugzilla.redhat.com/show_bug.cgi?id=1428564 • CWE-287: Improper Authentication CWE-306: Missing Authentication for Critical Function •