CVE-2019-10174: Infinispan
High severity, CVSS 8.8. EPSS: 3.1% chance of exploitation in the next 30 days.
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.
Affected products
- Infinispan Infinispan: before 8.2.12 (fixed in 8.2.12); from 9.0.0, before 9.4.17 (fixed in 9.4.17)
- Netapp Active Iq Unified Manager: affected versions not specified
- Red Hat Fuse: version 1.0 only
- Red Hat JBoss Data Grid: affected versions not specified
- Red Hat JBoss Enterprise Application Platform: affected versions not specified; version 7.2 only
- Red Hat Openshift Application Runtimes: affected versions not specified
- Red Hat Single Sign-On: affected versions not specified
Published 2019-11-25. Last modified 2026-06-17.