First published: Fri Apr 26 2019(Updated: )
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/eap7-glassfish-jsf | <0:2.3.5-11.SP3_redhat_00009.1.el6ea | 0:2.3.5-11.SP3_redhat_00009.1.el6ea |
redhat/eap7-infinispan | <0:9.3.9-1.Final_redhat_00001.1.el6ea | 0:9.3.9-1.Final_redhat_00001.1.el6ea |
redhat/eap7-glassfish-jsf | <0:2.3.5-11.SP3_redhat_00009.1.el7ea | 0:2.3.5-11.SP3_redhat_00009.1.el7ea |
redhat/eap7-infinispan | <0:9.3.9-1.Final_redhat_00001.1.el7ea | 0:9.3.9-1.Final_redhat_00001.1.el7ea |
redhat/eap7-glassfish-jsf | <0:2.3.5-11.SP3_redhat_00009.1.el8ea | 0:2.3.5-11.SP3_redhat_00009.1.el8ea |
redhat/eap7-infinispan | <0:9.3.9-1.Final_redhat_00001.1.el8ea | 0:9.3.9-1.Final_redhat_00001.1.el8ea |
redhat/Infinispan | <10.0.0. | 10.0.0. |
redhat/Infinispan | <9.4.17. | 9.4.17. |
redhat/Infinispan | <8.2.12. | 8.2.12. |
Infinispan Infinispan | <8.2.12 | |
Infinispan Infinispan | >=9.0.0<9.4.17 | |
Redhat Fuse | =1.0 | |
Redhat Jboss Data Grid | ||
Redhat Jboss Enterprise Application Platform | ||
Redhat Openshift Application Runtimes | ||
Redhat Single Sign-on | ||
Redhat Jboss Enterprise Application Platform | =7.2 | |
Redhat Enterprise Linux | =6.0 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux | =8.0 | |
Netapp Active Iq Unified Manager Linux | ||
Netapp Active Iq Unified Manager Vmware Vsphere | ||
Netapp Active Iq Unified Manager Windows |
There is no known mitigation for this issue.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The vulnerability ID is CVE-2019-10174.
The severity of CVE-2019-10174 is high with a severity value of 8.8.
Infinispan version 8.2.12 up to exclusive version 10.0.0 is affected by CVE-2019-10174.
To fix CVE-2019-10174, update your Infinispan software to version 10.0.0 or higher.
You can find more information about CVE-2019-10174 in the references provided: [Link 1](https://access.redhat.com/support/policy/updates/jboss_notes), [Link 2](https://access.redhat.com/errata/RHSA-2019:3901), [Link 3](https://access.redhat.com/security/cve/cve-2019-10174).