← Back

CVE-2017-15692

nvd nist
Published: Feb 27, 2018Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains access to the Geode locator, they may be able to cause remote code execution if certain classes are present on the classpath.

Affected (1)

Products: Apache: Geode
1 product
Geode
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.4.0

Timeline

No history available yet.