CVE-2017-15089
15.02.2018, 17:29
It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.Enginsight
Vendor | Product | Version |
---|---|---|
infinispan | infinispan | 𝑥 ≤ 9.1.6 |
infinispan | infinispan | 9.2.0:alpha1 |
infinispan | infinispan | 9.2.0:alpha2 |
infinispan | infinispan | 9.2.0:beta1 |
infinispan | infinispan | 9.2.0:beta2 |
infinispan | infinispan | 9.2.0:cr1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References