A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.
References
Link | Resource |
---|---|
https://access.redhat.com/errata/RHSA-2020:0481 | Vendor Advisory |
https://access.redhat.com/errata/RHSA-2020:0727 | Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10174 | Issue Tracking Vendor Advisory |
https://security.netapp.com/advisory/ntap-20220210-0018/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
|
History
20 Feb 2022, 06:31
Type | Values Removed | Values Added |
---|---|---|
References | (REDHAT) https://access.redhat.com/errata/RHSA-2020:0727 - Vendor Advisory | |
References | (CONFIRM) https://security.netapp.com/advisory/ntap-20220210-0018/ - Third Party Advisory | |
References | (REDHAT) https://access.redhat.com/errata/RHSA-2020:0481 - Vendor Advisory | |
CPE | cpe:2.3:a:redhat:fuse:1.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* cpe:2.3:a:redhat:jboss_enterprise_application_platform:-:*:*:*:text-only:*:*:* cpe:2.3:a:redhat:openshift_application_runtimes:-:*:*:*:text-only:*:*:* cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2:*:*:*:*:*:*:* cpe:2.3:a:redhat:single_sign-on:-:*:*:*:text-only:*:*:* cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:* cpe:2.3:a:redhat:jboss_data_grid:-:*:*:*:text-only:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : 6.5
v3 : 8.8 |
10 Feb 2022, 10:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2019-11-25 11:15
Updated : 2024-02-04 20:39
NVD link : CVE-2019-10174
Mitre link : CVE-2019-10174
CVE.ORG link : CVE-2019-10174
JSON object : View
Products Affected
redhat
- jboss_enterprise_application_platform
- jboss_data_grid
- fuse
- openshift_application_runtimes
- enterprise_linux
- single_sign-on
infinispan
- infinispan
netapp
- active_iq_unified_manager
CWE
CWE-470
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')