Security Advisory

CVE-2016-0750

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-09-11 13:00:00
Last updated 2024-08-05 22:30:04
Assigner redhat
CVSS score 4.2
State PUBLISHED

Description

The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks.