← back
CVE-2019-10174highCWE-470

CVE-2019-10174

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 3.1%
exploitation probability
3.1%top 14% of all CVEs
observed exploitation
nono source reports it
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
[UNKNOWN] · infinispan