CVE-2019-10174

Description

A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispans privileges. The attacker can use reflection to introduce new, malicious behavior into the application.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.037

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-10174 are fixed in Infinispan--core 8.2.12Windows
Vulnerabilities CVE-2019-10174 are fixed in Infinispan--core 9.4.17Windows
Multiple Vulnerabilities are affected in Netapp Active Iq Unified Manager 2.3Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 7.2Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Data Grid 2.3Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 2.3Windows
Vulnerabilities CVE-2019-10174 are fixed in Infinispan--core for Linux 8.2.12Linux
Vulnerabilities CVE-2019-10174 are fixed in Infinispan--core for Linux 9.4.17Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234