CWE-470
70 CVEs • Abstraction: Base
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.
CVEs (70)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 non-authenticated user can remotely instanti...Show more |
codeBeamer before 9.5.0-RC3 does not properly restrict the ability to execute custom Java code and access the Java class loader via computed fields. |
3Infinispan NetappRedhat7Active Iq Unified Manager FuseInfinispan+4 moreJun 17, 2026 Nov 25, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The att...Show more |
1Redhat 1Jboss Operations Network Jun 17, 2026 Oct 3, 2019 N/A· v4 7.3 HIGH· v3 6.8 MEDIUM· v2 It was found that the fix for CVE-2014-0114 had been reverted in JBoss Operations Network 3 (JON). This flaw allows attackers to manipulate ClassLoader properties on a vulnerable server. Exploits that have been published...Show more |
2Jenkins Redhat2Openshift Container Platform Pipeline\Jun 17, 2026 Mar 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sandboxed scripts. |
2Jenkins Redhat2Openshift Container Platform Script SecurityJun 17, 2026 Mar 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandboxed scripts. |
4Bouncycastle NetappOpensuse+1 more24Api Gateway Banking PlatformBc Java+21 moreMay 12, 2025 Jul 9, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vuln...Show more |
2F5 Vmware16Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+13 moreJun 17, 2026 Apr 13, 2018 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allo...Show more |
1Redhat 6Hibernate Validator Jboss Enterprise Application PlatformSatellite+3 moreNov 21, 2024 Jan 10, 2018 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernat...Show more |
ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection methods to access trusted Java objects without using the CreateObject fu...Show more |