Vulnerability CVE-2019-10174


Published: 2019-11-25   Modified: 2019-11-29

Description:
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.

Type:

CWE-470

(Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection'))

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Infinispan -> Infinispan 

 References:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10174

Copyright 2024, cxsecurity.com

 

Back to Top