← Back to CVE List

CVE-2017-15089

Published: 2018-02-15T17:29Z
Last Modified: 2024-11-21T03:14Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt