CVE-2017-15089

Summary

It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.

Affected Software

VendorProductVersion RangeStatus
Infinispaninfinispanbefore 9.2.0.CR1affected

Weaknesses

  • CWE-502: CWE-502

ADP Enrichment

CVE Program Container

Additional References

References