CVE-2017-2638 PUBLISHED CVSS 6.5 MEDIUM

It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.

EPSS 0.49% · 65.6th percentile

Risk Scores

CVSS v3.0
6.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS Score
0.49%
65.6th percentile

Affected Products

VendorProductVersions
[UNKNOWN]infinispanInfinispan 9.0.0.Final
redhatjboss_data_grid7.1
Mavenorg.infinispan:infinispan-server-core0
infinispaninfinispan0

Timeline

References

Open in Interactive Console →