Vulnerabilities > Infinispan > Infinispan > 8.2.12

DATE CVE VULNERABILITY TITLE RISK
2020-12-03 CVE-2020-25711 Missing Authorization vulnerability in multiple products
A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations.
network
low complexity
infinispan redhat netapp CWE-862
6.5
2020-01-02 CVE-2019-10158 Session Fixation vulnerability in multiple products
A flaw was found in Infinispan through version 9.4.14.Final.
network
low complexity
infinispan redhat CWE-384
critical
9.8
2018-09-11 CVE-2016-0750 Deserialization of Untrusted Data vulnerability in Infinispan
The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events.
network
low complexity
infinispan CWE-502
8.8