CVE-2014-3558

Hibernate Validator 4.1.0-4.2.1 4.3.0-4.3.2 - Java Security Manager Bypass via ReflectionHelper

Title source: llm
STIX 2.1

Description

ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 allows attackers to bypass Java Security Manager (JSM) restrictions and execute restricted reflection calls via a crafted application.

References (8)

Core 8
Core References
Third Party Advisory x_refsource_confirm
https://hibernate.atlassian.net/browse/HV-912
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0720.html
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1288.html
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0125.html
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1285.html
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1286.html
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1287.html

Scores

EPSS 0.0291
EPSS Percentile 85.5%

Details

CWE
CWE-264
Status published
Products (4)
org.hibernate/hibernate-validator 4.1.0 - 4.2.1Maven
redhat/hibernate_validator 4.1.0
redhat/hibernate_validator 4.2.0 (4 CPE variants)
redhat/hibernate_validator 4.3.0 - 4.3.2
Published Sep 30, 2014
Tracked Since Feb 18, 2026