Deserialization of untrusted data in JBoss Data Grid - CVE-2017-15089
Published: February 14, 2018
Vulnerability identifier: #VU10576
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-15089
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated attacker to execute arbitrary data on the target system.
The weakness exists due to unsafely read deserialized data on information from the cache. A remote attacker can inject specially-crafted serialized objects into data cache and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists due to unsafely read deserialized data on information from the cache. A remote attacker can inject specially-crafted serialized objects into data cache and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
JBoss Data Grid
openEuler
Fuse
eap7-jboss-ec2-eap (Red Hat package)
infinispan
infinispan-help
openEuler
Fuse
eap7-jboss-ec2-eap (Red Hat package)
infinispan
infinispan-help
How to mitigate CVE-2017-15089
Update to version 7.1.2.
Fuse - update to 6.3.0
eap7-jboss-ec2-eap (Red Hat package) - addressed in versions 7.1.1-3.1.GA_redhat_3.ep7.el6, 7.1.1-3.1.GA_redhat_3.ep7.el7
infinispan - update to 8.2.4-8
infinispan-help - update to 8.2.4-8
eap7-jboss-ec2-eap (Red Hat package) - addressed in versions 7.1.1-3.1.GA_redhat_3.ep7.el6, 7.1.1-3.1.GA_redhat_3.ep7.el7
infinispan - update to 8.2.4-8
infinispan-help - update to 8.2.4-8
External References
Related Security Bulletins
- Multiple vulnerabilities in Red Hat JBoss Data Grid
- Red Hat JBoss Enterprise Application Platform 7.1.1 for Red Hat Enterprise Linux 6 and Red Hat JBoss Enterprise Application Platform 7.1.1 for Red Hat Enterprise Linux 7 update for eap7-jboss-ec2-eap
- openEuler 20.03 LTS SP1 update for infinispan
- Deserialization of untrusted data in Fuse 6