First published: Fri Apr 26 2019(Updated: )
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/eap7-glassfish-jsf | <0:2.3.5-11.SP3_redhat_00009.1.el6ea | 0:2.3.5-11.SP3_redhat_00009.1.el6ea |
redhat/eap7-infinispan | <0:9.3.9-1.Final_redhat_00001.1.el6ea | 0:9.3.9-1.Final_redhat_00001.1.el6ea |
redhat/eap7-glassfish-jsf | <0:2.3.5-11.SP3_redhat_00009.1.el7ea | 0:2.3.5-11.SP3_redhat_00009.1.el7ea |
redhat/eap7-infinispan | <0:9.3.9-1.Final_redhat_00001.1.el7ea | 0:9.3.9-1.Final_redhat_00001.1.el7ea |
redhat/eap7-glassfish-jsf | <0:2.3.5-11.SP3_redhat_00009.1.el8ea | 0:2.3.5-11.SP3_redhat_00009.1.el8ea |
redhat/eap7-infinispan | <0:9.3.9-1.Final_redhat_00001.1.el8ea | 0:9.3.9-1.Final_redhat_00001.1.el8ea |
redhat/Infinispan | <10.0.0. | 10.0.0. |
redhat/Infinispan | <9.4.17. | 9.4.17. |
redhat/Infinispan | <8.2.12. | 8.2.12. |
Infinispan Infinispan | <8.2.12 | |
Infinispan Infinispan | >=9.0.0<9.4.17 | |
Redhat Fuse | =1.0 | |
Red Hat JBoss Data Grid | ||
Red Hat JBoss Enterprise Application Platform | ||
Red Hat Openshift Application Runtimes | ||
Red Hat Single Sign-On | ||
Red Hat JBoss Enterprise Application Platform | =7.2 | |
Red Hat Enterprise Linux | =6.0 | |
Red Hat Enterprise Linux | =7.0 | |
Red Hat Enterprise Linux | =8.0 | |
Netapp Active Iq Unified Manager Linux | ||
Netapp Active Iq Unified Manager Vmware Vsphere | ||
Netapp Active Iq Unified Manager Windows |
There is no known mitigation for this issue.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The vulnerability ID is CVE-2019-10174.
The severity of CVE-2019-10174 is high with a severity value of 8.8.
Infinispan version 8.2.12 up to exclusive version 10.0.0 is affected by CVE-2019-10174.
To fix CVE-2019-10174, update your Infinispan software to version 10.0.0 or higher.
You can find more information about CVE-2019-10174 in the references provided: [Link 1](https://access.redhat.com/support/policy/updates/jboss_notes), [Link 2](https://access.redhat.com/errata/RHSA-2019:3901), [Link 3](https://access.redhat.com/security/cve/cve-2019-10174).