CVE-2014-3558: Red Hat Hibernate Validator
Medium severity, CVSS 5.0. EPSS: 2.9% chance of exploitation in the next 30 days.
ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 allows attackers to bypass Java Security Manager (JSM) restrictions and execute restricted reflection calls via a crafted application.
Affected products
- Red Hat Hibernate Validator: from 4.3.0, before 4.3.2 (fixed in 4.3.2); from 5.0.0, up to and including 5.0.3; from 5.1.0, before 5.1.2 (fixed in 5.1.2); version 4.1.0 only; version 4.2.0 only
Published 2014-09-30. Last modified 2026-06-17.