REDHAT-BUG-1120495: Low severity red hat hibernate validator vulnerability

Published Jul 17, 2014
·
Updated

IssueDescription:

It was discovered that the implementation of org.hibernate.validator.util.ReflectionHelper together with the permissions required to run Hibernate Validator under the Java Security Manager could allow a malicious application deployed in the same application container to execute several actions with escalated privileges, which might otherwise not be possible. This flaw could be used to perform various attacks, including but not restricted to, arbitrary code execution in systems that are otherwise secured by the Java Security Manager.

Affected Software

1 affected component
Hibernate Validator

Event History

Jul 17, 2014
Data Sourced
05:08 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-1120495?

The vulnerability REDHAT-BUG-1120495 has been classified with a medium severity level.

2

How do I fix REDHAT-BUG-1120495?

To fix REDHAT-BUG-1120495, update Hibernate Validator to the latest recommended version that addresses this vulnerability.

3

What is affected by REDHAT-BUG-1120495?

REDHAT-BUG-1120495 affects applications utilizing Hibernate Validator in an environment with the Java Security Manager.

4

Is REDHAT-BUG-1120495 an exploit risk?

Yes, REDHAT-BUG-1120495 poses an exploit risk by allowing unauthorized code execution in specific configurations.

5

Who is responsible for addressing REDHAT-BUG-1120495?

Developers and system administrators using affected versions of Hibernate Validator should address REDHAT-BUG-1120495 promptly.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203