Vulnerabilities > CVE-2016-0750 - Deserialization of Untrusted Data vulnerability in Infinispan
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Redhat
advisories |
|
References
- http://www.securityfocus.com/bid/101910
- http://www.securityfocus.com/bid/101910
- https://access.redhat.com/errata/RHSA-2017:3244
- https://access.redhat.com/errata/RHSA-2017:3244
- https://access.redhat.com/errata/RHSA-2018:0501
- https://access.redhat.com/errata/RHSA-2018:0501
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-0750
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-0750
- https://github.com/infinispan/infinispan/pull/5116
- https://github.com/infinispan/infinispan/pull/5116
- https://issues.jboss.org/browse/ISPN-7781
- https://issues.jboss.org/browse/ISPN-7781