Remote Code Execution Vulnerability in Hazelcast by Hazelcast
CVE-2016-10750

8.1HIGH

Key Information:

Vendor

Hazelcast

Status
Vendor
CVE Published:
22 May 2019

What is CVE-2016-10750?

The Hazelcast product prior to version 3.11 is susceptible to a remote code execution flaw due to vulnerabilities in the cluster join procedure. This issue arises when an attacker dispatches a forged JoinRequest to a vulnerable Hazelcast instance. If certain vulnerable classes are present in the classpath, the adversary can exploit this to execute arbitrary code remotely, posing significant security risks to affected systems.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.