ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 allows attackers to bypass Java Security Manager (JSM) restrictions and execute restricted reflection calls via a crafted application.
2014-09-30T14:55:08.657
2025-04-12T10:46:40.837
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | hibernate_validator | < 4.3.2 | Yes |
Application | redhat | hibernate_validator | ≤ 5.0.3 | Yes |
Application | redhat | hibernate_validator | < 5.1.2 | Yes |
Application | redhat | hibernate_validator | 4.1.0 | Yes |
Application | redhat | hibernate_validator | 4.2.0 | Yes |
Application | redhat | hibernate_validator | 4.2.0 | Yes |
Application | redhat | hibernate_validator | 4.2.0 | Yes |
Application | redhat | hibernate_validator | 4.2.0 | Yes |