infinispan: invokeAccessibly method from ReflectionUtil class allows to invoke private methods
Published Nov 25, 2019
8.8
HIGHCVSS 3.1
EPSS 3.09%
Description
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.
Affected products
- Vendor n/a Product Infinispan Defaultn/a
- Version 10.0.0.FinalStatusaffectedConstraints-
- Version 9.4.17.FinalStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| n/a | Infinispan | n/a |
|
Configuration 1
- < 8.2.12
- ≥ 9.0.0 · < 9.4.17
Configuration 2
- 1.0
- n/a
- n/a
- n/a
- n/a
Configuration 3
- 7.2
Running on/with
- 6.0
- 7.0
- 8.0
Configuration 4
- n/a
- n/a
- n/a
No data.
EAP-CD 19 Tech Preview
infinispan-core
Fixed · RHSA-2020:2333
Red Hat Data Grid 7.3.3
infinispan-core
Fixed · RHSA-2020:0727
Red Hat Fuse 6.3
infinispan-core
Fixed · RHSA-2020:0481
Red Hat Fuse 7.6.0
infinispan-core
Fixed · RHSA-2020:0983
Red Hat JBoss EAP 7.2
infinispan-core
Fixed · RHSA-2020:2062
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-infinispan-0:8.2.11-1.SP2_redhat_00001.1.ep7.el7
Fixed · RHSA-2024:5856
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6
eap7-glassfish-jsf-0:2.3.5-11.SP3_redhat_00009.1.el6eap
Fixed · RHSA-2020:2063
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6
eap7-infinispan-0:9.3.9-1.Final_redhat_00001.1.el6eap
Fixed · RHSA-2020:2063
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7
eap7-glassfish-jsf-0:2.3.5-11.SP3_redhat_00009.1.el7eap
Fixed · RHSA-2020:2063
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7
eap7-infinispan-0:9.3.9-1.Final_redhat_00001.1.el7eap
Fixed · RHSA-2020:2063
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8
eap7-glassfish-jsf-0:2.3.5-11.SP3_redhat_00009.1.el8eap
Fixed · RHSA-2020:2063
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8
eap7-infinispan-0:9.3.9-1.Final_redhat_00001.1.el8eap
Fixed · RHSA-2020:2063
Red Hat Openshift Application Runtimes Vert.x 3.8.3
infinispan-core
Fixed · RHSA-2019:3901
Red Hat Single Sign On 7.3
infinispan-core
Fixed · RHSA-2020:2113
Red Hat Decision Manager 7
infinispan-core
Not affected
Red Hat JBoss Data Virtualization 6
infinispan-core
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
infinispan-core
Not affected
Red Hat JBoss Fuse Service Works 6
infinispan-core
Out of support scope
Red Hat JBoss Operations Network 3
infinispan-core
Affected
Red Hat OpenStack Platform 13 (Queens)
opendaylight
Will not fix
Red Hat OpenStack Platform 14 (Rocky)
opendaylight
Will not fix
Red Hat OpenStack Platform 9 (Mitaka)
opendaylight
Will not fix
Red Hat Process Automation 7
infinispan-core
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| EAP-CD 19 Tech Preview | infinispan-core | Fixed | RHSA-2020:2333 |
| Red Hat Data Grid 7.3.3 | infinispan-core | Fixed | RHSA-2020:0727 |
| Red Hat Fuse 6.3 | infinispan-core | Fixed | RHSA-2020:0481 |
| Red Hat Fuse 7.6.0 | infinispan-core | Fixed | RHSA-2020:0983 |
| Red Hat JBoss EAP 7.2 | infinispan-core | Fixed | RHSA-2020:2062 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-infinispan-0:8.2.11-1.SP2_redhat_00001.1.ep7.el7 | Fixed | RHSA-2024:5856 |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | eap7-glassfish-jsf-0:2.3.5-11.SP3_redhat_00009.1.el6eap | Fixed | RHSA-2020:2063 |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | eap7-infinispan-0:9.3.9-1.Final_redhat_00001.1.el6eap | Fixed | RHSA-2020:2063 |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | eap7-glassfish-jsf-0:2.3.5-11.SP3_redhat_00009.1.el7eap | Fixed | RHSA-2020:2063 |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | eap7-infinispan-0:9.3.9-1.Final_redhat_00001.1.el7eap | Fixed | RHSA-2020:2063 |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | eap7-glassfish-jsf-0:2.3.5-11.SP3_redhat_00009.1.el8eap | Fixed | RHSA-2020:2063 |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | eap7-infinispan-0:9.3.9-1.Final_redhat_00001.1.el8eap | Fixed | RHSA-2020:2063 |
| Red Hat Openshift Application Runtimes Vert.x 3.8.3 | infinispan-core | Fixed | RHSA-2019:3901 |
| Red Hat Single Sign On 7.3 | infinispan-core | Fixed | RHSA-2020:2113 |
| Red Hat Decision Manager 7 | infinispan-core | Not affected | n/a |
| Red Hat JBoss Data Virtualization 6 | infinispan-core | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | infinispan-core | Not affected | n/a |
| Red Hat JBoss Fuse Service Works 6 | infinispan-core | Out of support scope | n/a |
| Red Hat JBoss Operations Network 3 | infinispan-core | Affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) | opendaylight | Will not fix | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | opendaylight | Will not fix | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | opendaylight | Will not fix | n/a |
| Red Hat Process Automation 7 | infinispan-core | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat OpenStack Platform's OpenDaylight contains the vulnerable library. This library is a requirement of other dependencies (Karaf and Hibernate). Under supported deployments, the vulnerable functionality is not utilized. Based on this, no OpenDaylight versions will not be fixed.
Red Hat mitigation
There is no known mitigation for this issue.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:S/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (15 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.09% (0.03089) | 87.26th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.09% (0.03089) | 85.97th | v5 (v2026.06.15) |
| Oct 5, 2025 | 1.04% (0.01037) | 76.66th | v4 (v2025.03.14) |
| Oct 4, 2025 | 2.19% (0.02191) | 83.80th | v4 (v2025.03.14) |
| Jul 20, 2024 | 0.34% (0.00336) | 71.57th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.34% (0.00336) | 70.48th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.34% (0.00336) | 66.67th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00950) | 32.28th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.95% (0.00950) | 28.61th | v2 (v2022.01.01) |
| Feb 11, 2022 | 14.47% (0.14469) | 91.19th | v2 (v2022.01.01) |
| Feb 4, 2022 | 11.75% (0.11752) | 89.17th | v2 (v2022.01.01) |
| Feb 3, 2022 | 3.63% (0.03630) | 71.73th | v5 (v2026.06.15) |
| Jan 6, 2022 | 3.63% (0.03630) | 71.48th | v1 |
| Sep 1, 2021 | 0.83% (0.00833) | 57.50th | v1 |
| Apr 14, 2021 | 0.83% (0.00833) | 0.00th | v1 |
References (11)
- https://access.redhat.com/errata/RHSA-2020:0481 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2020:0727 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2019-10174 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1703469 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10174 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://github.com/advisories/GHSA-h47x-2j37-fw5m Advisory
- https://github.com/infinispan/infinispan/commit/5dbb05cfaca01a1a66732b82a0f5ba615ccbd214
- https://github.com/infinispan/infinispan/commit/7bdc2822ccf79127a488130239c49a5e944e3ca2
- https://nvd.nist.gov/vuln/detail/CVE-2019-10174
- https://security.netapp.com/advisory/ntap-20220210-0018/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-10174
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2020:0481 | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| https://access.redhat.com/errata/RHSA-2020:0727 | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2019-10174 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1703469 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10174 | x_refsource_CONFIRMIssue TrackingVendor Advisory | |
| https://github.com/advisories/GHSA-h47x-2j37-fw5m | Advisory | |
| https://github.com/infinispan/infinispan/commit/5dbb05cfaca01a1a66732b82a0f5ba615ccbd214 | ||
| https://github.com/infinispan/infinispan/commit/7bdc2822ccf79127a488130239c49a5e944e3ca2 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2019-10174 | ||
| https://security.netapp.com/advisory/ntap-20220210-0018/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-10174 |
Change history (0)
No recorded changes yet.