Vulnerability Description
ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 allows attackers to bypass Java Security Manager (JSM) restrictions and execute restricted reflection calls via a crafted application.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Hibernate Validator | >= 4.3.0, < 4.3.2 |
Related Weaknesses (CWE)
References
- http://rhn.redhat.com/errata/RHSA-2014-1285.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1286.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1287.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1288.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0125.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0720.htmlThird Party Advisory
- https://github.com/victims/victims-cve-db/blob/master/database/java/2014/3558.yaThird Party Advisory
- https://hibernate.atlassian.net/browse/HV-912Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1285.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1286.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1287.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1288.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0125.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0720.htmlThird Party Advisory
- https://github.com/victims/victims-cve-db/blob/master/database/java/2014/3558.yaThird Party Advisory
FAQ
What is CVE-2014-3558?
CVE-2014-3558 is a vulnerability with a CVSS score of 5.0 (MEDIUM). ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 allows attackers to bypass Java Security Manager (J...
How severe is CVE-2014-3558?
CVE-2014-3558 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-3558?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Hibernate Validator.