CVE-2014-3558
Published Sep 30, 2014
Last updated 6 years ago
Overview
- Description
- ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 allows attackers to bypass Java Security Manager (JSM) restrictions and execute restricted reflection calls via a crafted application.
- Source
- secalert@redhat.com
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-264
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:redhat:hibernate_validator:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7C54719E-9F01-4BFE-9E87-1C6F148FB94F", "versionEndExcluding": "4.3.2", "versionStartIncluding": "4.3.0" }, { "criteria": "cpe:2.3:a:redhat:hibernate_validator:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4295758F-72F1-4084-8DB7-B3D77CB496F1", "versionEndIncluding": "5.0.3", "versionStartIncluding": "5.0.0" }, { "criteria": "cpe:2.3:a:redhat:hibernate_validator:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "14B7B4E2-20A6-4DA1-891A-704CBA796610", "versionEndExcluding": "5.1.2", "versionStartIncluding": "5.1.0" }, { "criteria": "cpe:2.3:a:redhat:hibernate_validator:4.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "85723F05-6787-4253-8440-54C0C09A77FF" }, { "criteria": "cpe:2.3:a:redhat:hibernate_validator:4.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "90B439A6-38FA-49D5-939C-3E0EDEB817D3" }, { "criteria": "cpe:2.3:a:redhat:hibernate_validator:4.2.0:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "71E20279-589F-4FDF-B780-72CD51BA8A0A" }, { "criteria": "cpe:2.3:a:redhat:hibernate_validator:4.2.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "11D43A6E-2DF2-44F7-904D-01EF1DBB80A6" }, { "criteria": "cpe:2.3:a:redhat:hibernate_validator:4.2.0:cr1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "09A24383-9019-40D2-A869-576CC3197946" } ], "operator": "OR" } ] } ]