Apache Geode OQL Method Invocation Vulnerability in Secure Mode
CVE-2017-9795
7.5HIGH
What is CVE-2017-9795?
A vulnerability exists in Apache Geode when operating in secure mode prior to version 1.3.0, where users with read access can execute OQL queries. These queries potentially grant unauthorized read and write access to sensitive objects in secured regions, and may also allow execution of remote code, posing significant security risks to affected systems.
Affected Version(s)
Apache Geode 1.0.0 to 1.2.1