CVE-2017-15089
It was found that the Hotrod client in Infinispan would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.
Find out more about CVE-2017-15089 from the MITRE CVE dictionary dictionary and NIST NVD.
CVSS v3 metrics
| CVSS3 Base Score | 8 |
|---|---|
| CVSS3 Base Metrics | CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H |
| Attack Vector | Network |
| Attack Complexity | High |
| Privileges Required | Low |
| User Interaction | Required |
| Scope | Changed |
| Confidentiality | High |
| Integrity Impact | High |
| Availability Impact | High |
Red Hat Security Errata
| Platform | Errata | Release Date |
|---|---|---|
| Red Hat JBoss Data Grid 7.1 | RHSA-2018:0294 | 2018-02-12 |
| Red Hat Single Sign-On 7.2 | RHSA-2018:0501 | 2018-03-13 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server | RHSA-2018:0480 | 2018-03-12 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server (eap7-jboss-ec2-eap) | RHSA-2018:0481 | 2018-03-12 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server (eap7-jboss-ec2-eap) | RHSA-2018:0481 | 2018-03-12 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server | RHSA-2018:0479 | 2018-03-12 |
| Red Hat JBoss EAP 7 | RHSA-2018:0478 | 2018-03-12 |
Affected Packages State
| Platform | Package | State |
|---|---|---|
| Red Hat Virtualization 4 | eap7-infinispan-core | Will not fix |
| Red Hat Single Sign-On 7 | infinispan-core | Affected |
| Red Hat JBoss Portal Platform 6 | infinispan-core | Will not fix |
| Red Hat JBoss Operations Network 3 | infinispan-core | Not affected |
| Red Hat JBoss Fuse Service Works 6 | infinispan-core | Will not fix |
| Red Hat JBoss Fuse 6 | Camel | Affected |
| Red Hat JBoss EAP 6 | infinispan-core | Under investigation |
| Red Hat JBoss Data Virtualization 6 | infinispan-core | Not affected |
| Red Hat JBoss Data Grid 6 | infinispan-core | Will not fix |
