hazelcast: java deserialization in join cluster procedure leading to remote code execution
Published May 22, 2019
8.1
HIGHCVSS 3.0
EPSS 3.95%
Description
In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a listening Hazelcast instance with a crafted JoinRequest, and vulnerable classes exist in the classpath, the attacker can run arbitrary code.
Affected products
No data.
No data.
Red Hat Fuse 7.4.0
hazelcast
Fixed · RHSA-2019:2413
Red Hat JBoss Fuse 6
hazelcast
Affected
Red Hat OpenShift Application Runtimes
hazelcast
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7.4.0 | hazelcast | Fixed | RHSA-2019:2413 |
| Red Hat JBoss Fuse 6 | hazelcast | Affected | n/a |
| Red Hat OpenShift Application Runtimes | hazelcast | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The module vertx-hazelcast is not supported in Red Hat OpenShift Application Runtimes (RHOAR) products.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (17 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.95% (0.03951) | 90.09th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.71% (0.03711) | 88.30th | v5 (v2026.06.15) |
| Sep 15, 2025 | 2.44% (0.02445) | 84.62th | v4 (v2025.03.14) |
| Jul 1, 2025 | 4.34% (0.04336) | 88.48th | v4 (v2025.03.14) |
| Jun 28, 2025 | 5.81% (0.05812) | 90.07th | v4 (v2025.03.14) |
| Jun 7, 2025 | 3.85% (0.03848) | 87.64th | v4 (v2025.03.14) |
| Mar 30, 2025 | 5.25% (0.05248) | 89.01th | v4 (v2025.03.14) |
| Mar 29, 2025 | 24.38% (0.24375) | 93.70th | v4 (v2025.03.14) |
| Mar 19, 2025 | 5.25% (0.05248) | 88.72th | v4 (v2025.03.14) |
| Mar 17, 2025 | 4.20% (0.04200) | 87.97th | v4 (v2025.03.14) |
| Dec 17, 2024 | 4.30% (0.04297) | 92.21th | v3 (v2023.03.01) |
| Dec 12, 2024 | 2.73% (0.02728) | 90.90th | v3 (v2023.03.01) |
| May 15, 2024 | 2.63% (0.02631) | 90.29th | v3 (v2023.03.01) |
| Mar 7, 2023 | 2.61% (0.02610) | 88.64th | v3 (v2023.03.01) |
| Mar 6, 2023 | 5.63% (0.05634) | 90.24th | v2 (v2022.01.01) |
| Apr 1, 2022 | 5.63% (0.05634) | 89.29th | v2 (v2022.01.01) |
| Feb 4, 2022 | 5.63% (0.05634) | 76.84th | v2 (v2022.01.01) |
References (8)
- https://access.redhat.com/errata/RHSA-2019:2413 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2016-10750 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1713215 Issue Tracking
- https://github.com/advisories/GHSA-jv65-pf7v-f7p8 Advisory
- https://github.com/hazelcast/hazelcast/issues/8024 x_refsource_MISCIssue TrackingThird Party Advisory
- https://github.com/hazelcast/hazelcast/pull/12230 x_refsource_MISCIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-10750
- https://www.cve.org/CVERecord?id=CVE-2016-10750
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2019:2413 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2016-10750 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1713215 | Issue Tracking | |
| https://github.com/advisories/GHSA-jv65-pf7v-f7p8 | Advisory | |
| https://github.com/hazelcast/hazelcast/issues/8024 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://github.com/hazelcast/hazelcast/pull/12230 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2016-10750 | ||
| https://www.cve.org/CVERecord?id=CVE-2016-10750 |
Change history (0)
No recorded changes yet.