Deserialization of untrusted data in JBoss Data Grid - CVE-2017-15089

 

Deserialization of untrusted data in JBoss Data Grid - CVE-2017-15089

Published: February 14, 2018


Vulnerability identifier: #VU10576
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-15089
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to execute arbitrary data on the target system.

The weakness exists due to unsafely read deserialized data on information from the cache. A remote attacker can inject specially-crafted serialized objects into data cache and execute arbitrary code with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise.

Affected software

JBoss Data Grid
openEuler
Fuse
eap7-jboss-ec2-eap (Red Hat package)
infinispan
infinispan-help

How to mitigate CVE-2017-15089

Update to version 7.1.2.

Fuse - update to 6.3.0
eap7-jboss-ec2-eap (Red Hat package) - addressed in versions 7.1.1-3.1.GA_redhat_3.ep7.el6, 7.1.1-3.1.GA_redhat_3.ep7.el7
infinispan - update to 8.2.4-8
infinispan-help - update to 8.2.4-8

External References

Related Security Bulletins