CVE-2016-0750
The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain
The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks.
MEDIUM · CVSS 4.2
EPSS 0.00528
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0