CVE-2017-15692
CRITICALApache Geode < 1.4.0 - Insecure Deserialization
Title source: ruleDescription
In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains access to the Geode locator, they may be able to cause remote code execution if certain classes are present on the classpath.
Scores
CVSS v3
9.8
EPSS
0.0466
EPSS Percentile
89.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (2)
apache/geode
< 1.4.0
org.apache.geode/geode-core
< 1.4.0Maven
Timeline
Published
Feb 27, 2018
Tracked Since
Feb 18, 2026