A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.
                
            References
                    | Link | Resource | 
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10174 | Issue Tracking Vendor Advisory | 
| https://access.redhat.com/errata/RHSA-2020:0481 | Vendor Advisory | 
| https://access.redhat.com/errata/RHSA-2020:0727 | Vendor Advisory | 
| https://security.netapp.com/advisory/ntap-20220210-0018/ | Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
                                
                                
  | 
                        
Configuration 2 (hide)
                                
                                
  | 
                        
Configuration 3 (hide)
| AND | 
                                
                                
 
  | 
                        
Configuration 4 (hide)
                                
                                
  | 
                        
Information
                Published : 2019-11-25 03:15
Updated : 2022-02-19 22:31
NVD link : CVE-2019-10174
Mitre link : CVE-2019-10174
JSON object : View
CWE
                
                    
                        
                        CWE-470
                        
            Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
Products Affected
                redhat
- jboss_data_grid
 - enterprise_linux
 - jboss_enterprise_application_platform
 - single_sign-on
 - openshift_application_runtimes
 - fuse
 
netapp
- active_iq_unified_manager
 
infinispan
- infinispan
 


