6.5
CVSSv3

CVE-2017-2638

Published: 16/07/2018 Updated: 09/10/2019
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 6.5 | Impact Score: 2.5 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

infinispan infinispan

redhat jboss data grid 7.1

Vendor Advisories

Synopsis Moderate: Red Hat JBoss Data Grid 71 Type/Severity Security Advisory: Moderate Topic Red Hat JBoss Data Grid 71 is now available for download from the Customer PortalRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVS ...
It was found that the REST API in infinispan did not properly enforce auth constraints An attacker could use this vulnerability to read or modify data in the default cache or a known cache name ...