Vulnerability Name: | CVE-2019-10174 (CCN-172431) | ||||||||||||
Assigned: | 2019-11-25 | ||||||||||||
Published: | 2019-11-25 | ||||||||||||
Updated: | 2022-02-20 | ||||||||||||
Summary: | A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application. | ||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-470 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-10174 Source: REDHAT Type: Vendor Advisory RHSA-2020:0481 Source: REDHAT Type: Vendor Advisory RHSA-2020:0727 Source: CCN Type: Red Hat Bugzilla - Bug 1703469 CVE-2019-10174 infinispan: invokeAccessibly method from ReflectionUtil class allows to invoke private methods Source: CONFIRM Type: Issue Tracking, Vendor Advisory https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10174 Source: XF Type: UNKNOWN infinispan-cve201910174-sec-bypass(172431) Source: CCN Type: Infinispan Web site infinispan Source: CONFIRM Type: Third Party Advisory https://security.netapp.com/advisory/ntap-20220210-0018/ Source: CCN Type: WhiteSource Vulnerability Database CVE-2019-10174 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration 4: Configuration CCN 1: ![]() | ||||||||||||
BACK |